CVE-2023-26083 is an information disclosure vulnerability in Arm Mali GPU kernel drivers affecting Midgard versions r6p0 through r32p0, Bifrost versions r0p0 through r42p0, Valhall versions r19p0 through r42p0, and Avalon versions r41p0 through r42p0. The flaw allows a local non-privileged user to perform otherwise valid GPU processing operations that expose sensitive kernel metadata to userspace. Available technical reporting indicates the issue is associated with a timeline stream functionality in the driver that was exposed to unprivileged userspace processes and could serialize kernel object pointers or related metadata into a userspace-readable buffer. This can disclose kernel addresses and internal object information that materially weakens kernel exploit mitigations and can be used to support further exploitation. There is evidence of limited, targeted exploitation in the wild.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2023-26083 affecting the Arm Mali GPU Kernel Driver. The repo contains three files: an MIT LICENSE, a detailed README, and one C source file (mali_tlstream_leak.c) that implements the exploit. There is no framework integration, no remote component, and no post-exploitation payload beyond information disclosure. The exploit is a local kernel information-leak PoC. It targets the Mali timeline stream interface exposed through /dev/mali0. In main(), the program opens the device, performs KBASE_IOCTL_VERSION_CHECK, sets create_flags to BASE_CONTEXT_CREATE_FLAG_NONE via KBASE_IOCTL_SET_FLAGS, and then calls KBASE_IOCTL_TLSTREAM_ACQUIRE. The vulnerability is that timeline stream acquisition should require monitor privileges (BASE_CONTEXT_CREATE_FLAG_MONITOR), but the driver fails to enforce that check. If successful, the ioctl returns a timeline-stream file descriptor that the unprivileged process can read. After acquiring the stream, the code sleeps briefly, reads multiple packets from the returned descriptor, prints a raw hex dump, and parses timeline packets. The parser understands several Mali timeline message types such as NEW_CTX, NEW_GPU, NEW_LPU, NEW_ATOM, NEW_AS, and relationship/configuration events. It extracts pointer-sized fields from packet payloads and heuristically flags values in kernel address ranges (for example addresses beginning with 0xffffff80 or 0xffffffc0) as leaked kernel pointers. This demonstrates disclosure of internal driver object addresses including kbase_context, GPU, LPU, address-space, and atom-related objects. Operationally, the exploit provides unauthorized access to sensitive kernel memory layout information and can help defeat KASLR. By itself it does not execute code, overwrite memory, or elevate privileges, so it is best classified as a PoC information disclosure exploit rather than a weaponized chain. The README also documents build instructions for Android/Linux ARM targets and explains that the PoC was tested on a Samsung Galaxy J7 Prime running Android 8.1.0 with a 3.18 kernel.
Standalone local proof-of-concept for CVE-2023-26083 affecting the Arm Mali GPU Kernel Driver. The repository is minimal: LICENSE, README.md, and a single C source file implementing the exploit. The code opens /dev/mali0, performs KBASE_IOCTL_VERSION_CHECK, sets create_flags to BASE_CONTEXT_CREATE_FLAG_NONE via KBASE_IOCTL_SET_FLAGS, then calls KBASE_IOCTL_TLSTREAM_ACQUIRE despite lacking monitor privileges. If the target driver is vulnerable, the ioctl returns a timeline stream fd that the program reads from and parses. The parser decodes tlstream packet headers and selected object/event message formats, then prints embedded pointer fields and marks likely kernel addresses when they match expected high address patterns (for example 0xffffff80 / 0xffffffc0 upper bits on tested 64-bit targets). Exposed objects include NEW_CTX, NEW_GPU, NEW_LPU, NEW_AS, and related linkage/configuration records. This makes the exploit useful for KASLR bypass and kernel-driver state disclosure, but it does not itself perform privilege escalation or arbitrary code execution. There are no network callbacks, remote C2 endpoints, or external services involved. The only fingerprintable target surface in the code is the local device node /dev/mali0 and the associated Mali ioctls. Overall, this is a genuine local information-disclosure exploit PoC with clear research intent and limited operationalization.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Android/Linux kernel vulnerability (CVE-2023-26083) providing a limited write primitive that can be leveraged to manipulate kernel structures (e.g., miscdevice ->fops / file_operations) to enable further privilege escalation via crafted function-pointer tables and type confusion in callbacks.
An Arm Mali GPU Kernel Driver information disclosure vulnerability that exposes sensitive kernel metadata; Arm states there is evidence of limited, targeted exploitation.
An information disclosure vulnerability in the Mali GPU driver's Timeline Stream functionality that leaks kernel pointers to unprivileged userspace, aiding exploitation.
ARM-side CVE assigned to fixes for kernel information leak 0-days used alongside exploitation of CVE-2022-22706 and CVE-2023-0266.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.