QID 379509

QID 379509: Khronos Group OpenCL/Vulkan Buffer Overflow Vulnerability (LeftoverLocals)

General-purpose graphics processing unit (GPGPU) platforms from AMD fail to adequately isolate process memory, thereby enabling a local attacker to read memory from other processes. In this situation, a GPU kernel can observe memory values from a different GPU kernel, even when these two kernels are isolated between applications, processes, or users.

QID Detection Logic:

Successful exploitation allows an attacker with access to GPU capabilities using a vulnerable GPU's programmable interface can access memory that is expected to be isolated from other users and processes.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to VU#446598 for more information pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 379509

    Software Advisories
    Advisory ID Software Component Link
    VU#446598 URL Logo kb.cert.org/vuls/id/446598