Firmware: Mali Command Stream Frontend (CSF) Firmwareother· Tier 2Software: Mali GPU Kernel Driverother· Tier 3— none listed —
— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Arm.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "0acb1a74-c545-4941-ae57-7ca5fad9d449",
"name": "Arm",
"company_handle": "arm",
"handle": "arm",
"url": "https://www.intigriti.com/programs/arm/arm/detail",
"status": "open",
"confidentiality_level": "public",
"tacRequired": false,
"twoFactorRequired": false,
"min_bounty": {
"value": 500,
"currency": "USD"
},
"max_bounty": {
"value": 20000,
"currency": "USD"
},
"targets": {
"in_scope": [
{
"type": "other",
"endpoint": "Firmware: Mali Command Stream Frontend (CSF) Firmware",
"description": "#### Arm GPU Firmware running on the Command Stream Frontend (CSF): 'CSFFW' (`mali_csffw.bin`)\n\nOnly vulnerabilities that are exploitable through userspace mapped Command Buffers, and/or Kbase syscalls available to unprivileged userspace attackers (in EL0) are in scope.\n\nNote: the version of 'CSFFW' used must be matched to your device:\n- Its version must match the Kbase driver version in use.\n- It must be the correct variant of CSFFW for the device's GPU.\n\nThe version of CSFFW that comes on a compatible device will satisfy this, providing the device has the latest available security updates installed.\n",
"impact": "Tier 2"
},
{
"type": "other",
"endpoint": "Software: Mali GPU Kernel Driver",
"description": "#### Arm Mali GPU Kernel Driver 'Kbase' (`mali_kbase.ko`)\n\nIn scope versions of the Arm Kbase driver version are:\n- The latest Arm Bifrost, Valhall, or 5th Gen GPU Kernel driver versions, as found on <https://developer.arm.com/downloads/-/mali-drivers/> or, \n- Arm Bifrost, Valhall, or 5th Gen GPU Kernel driver versions r49p1 and above that are running on devices supported by the OEM and have latest available security patches applied.\n\nOnly vulnerabilities that are exploitable through syscalls available to unprivileged userspace attackers (in EL0) are in scope.\n\nUse of the following configuration options is allowed. The use of other options is out of scope and may only be used during investigation.\n\n#### Kbase Build Configuration\nMali Kbase Default KConfig Build Options are used.\n\nThe following must specifically be set:\n- `CONFIG_MALI_DEBUG=n`\n\nAdditionally, the following options may be changed:\n- `CONFIG_MALI_CSF_SUPPORT=y` or `n` (please refer to FAQ for which setting must be used)\n- `CONFIG_MALI_EXPERT=y` or `n`\n- `CONFIG_LARGE_PAGE_SUPPORT=y` or `n`\n- `CONFIG_MALI_TRACE_POWER_GPU_WORK_PERIOD=y` or `n`\n- `CONFIG_MALI_NO_MALI`, either:\n - `=n` (default)\n - `=y`, (excludes vulnerabilities in the \"dummy model\" code itself)\n\n#### Kbase Dynamic Configuration\nThe default module parameter settings must be used.\n\nAdditionally, the following option(s) may be changed (chosen at 'insmod' time) :\n- `kbase_page_migration_enabled`\n",
"impact": "Tier 3"
}
],
"out_of_scope": []
}
}