Arm Mali CSF VMA Split Mishandling
Posted by deepcore on August 25, 2022 – 11:46 pm
In the Arm Mali driver’s handling of CSF user I/O mappings, VMA splitting is handled incorrectly, leading to a page being given back to the kernel’s page allocator while it is still mapped into userspace. On devices with recent Mali GPUs that support CSF, this is a security bug that should be very straightforward to exploit.
Post a reply
You must be logged in to post a comment.