CVE-2023-22808: Arm Avalon Android Gralloc Module
Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.
An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
Affected products
- Arm Avalon Android Gralloc Module: version r41p0 only
- Arm Bifrost Android Gralloc Module: from r24p0, up to and including r41p0
- Arm Valhall Android Gralloc Module: from r24p0, up to and including r41p0
Published 2023-04-11. Last modified 2026-06-17.