CVE-2023-22808: Arm Avalon Android Gralloc Module

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue was discovered in the Arm Android Gralloc Module. A non-privileged user can read a small portion of the allocator process memory. This affects Bifrost r24p0 through r41p0 before r42p0, Valhall r24p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

Affected products

  • Arm Avalon Android Gralloc Module: version r41p0 only
  • Arm Bifrost Android Gralloc Module: from r24p0, up to and including r41p0
  • Arm Valhall Android Gralloc Module: from r24p0, up to and including r41p0

Published 2023-04-11. Last modified 2026-06-17.