Memory Leak Affecting firmware-nonfree package, versions <20240610-1
Threat Intelligence
EPSS
0.07% (30th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN13-FIRMWARENONFREE-6184661
- published 23 Jan 2024
- disclosed 16 Jan 2024
Introduced: 16 Jan 2024
CVE-2023-4969 Open this link in a new tabHow to fix?
Upgrade Debian:13
firmware-nonfree
to version 20240610-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream firmware-nonfree
package and not the firmware-nonfree
package as distributed by Debian
.
See How to fix?
for Debian:13
relevant fixed versions and status.
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called local memory on various architectures.
References
- https://security-tracker.debian.org/tracker/CVE-2023-4969
- https://blog.trailofbits.com
- https://kb.cert.org/vuls/id/446598
- https://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_API.html#_fundamental_memory_regions
- https://registry.khronos.org/vulkan/specs/1.3-extensions/html/index.html
- https://www.kb.cert.org/vuls/id/446598
CVSS Scores
version 3.1