QID 379509
QID 379509: Khronos Group OpenCL/Vulkan Buffer Overflow Vulnerability (LeftoverLocals)
General-purpose graphics processing unit (GPGPU) platforms from AMD fail to adequately isolate process memory, thereby enabling a local attacker to read memory from other processes. In this situation, a GPU kernel can observe memory values from a different GPU kernel, even when these two kernels are isolated between applications, processes, or users.
QID Detection Logic:
Successful exploitation allows an attacker with access to GPU capabilities using a vulnerable GPU's programmable interface can access memory that is expected to be isolated from other users and processes.
Solution
Customers are advised to refer to VU#446598 for more information pertaining to this vulnerability.
Vendor References
- VU#446598 -
kb.cert.org/vuls/id/446598
CVEs related to QID 379509
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VU#446598 |
|