A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
Conclusion & alert: CVE-2023-4969 is rated High Exploit Risk (62.3/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.18%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.06% | 1.18% | -0.89% |
| 2 | 2026-02-03 | 1.74% | 2.06% | +0.32% |
| 3 | 2026-02-02 | — | 1.74% | — |
Full EPSS history (27 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.0 | 4.0 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.0 | 4.0 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2023-4969 not yet assigned priority: Debian including 1 source packages (firmware-nonfree), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2. | https://security-tracker.debian.org/tracker/CVE-2023-4969 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-4969 |
ubuntu
|
medium | CVE-2023-4969 medium priority: Ubuntu including 1 source packages (linux-firmware), 12 status rows across 12 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): deferred 7, ignored 4, needs-triage 1. | https://ubuntu.com/security/CVE-2023-4969 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| khronos | opencl | <= 3.0.11 | cpe:2.3:a:khronos:opencl:*:*:*:*:*:*:*:* |
| khronos | vulkan | <= 1.3.224 | cpe:2.3:a:khronos:vulkan:*:*:*:*:*:*:*:* |
| imaginationtech | ddk | <= 23.2 | cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:* |
| amd | instinct_mi300x_firmware | — | cpe:2.3:o:amd:instinct_mi300x_firmware:-:*:*:*:*:*:*:* |
| amd | instinct_mi300a_firmware | — | cpe:2.3:o:amd:instinct_mi300a_firmware:-:*:*:*:*:*:*:* |
| amd | instinct_mi250_firmware | — | cpe:2.3:o:amd:instinct_mi250_firmware:-:*:*:*:*:*:*:* |
| amd | instinct_mi210_firmware | — | cpe:2.3:o:amd:instinct_mi210_firmware:-:*:*:*:*:*:*:* |
| amd | instinct_mi100_firmware | — | cpe:2.3:o:amd:instinct_mi100_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_instinct_mi50_firmware | — | cpe:2.3:o:amd:radeon_instinct_mi50_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_instinct_mi25_firmware | — | cpe:2.3:o:amd:radeon_instinct_mi25_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_v620_firmware | — | cpe:2.3:o:amd:radeon_pro_v620_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_v520_firmware | — | cpe:2.3:o:amd:radeon_pro_v520_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_w7600_firmware | — | cpe:2.3:o:amd:radeon_pro_w7600_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_w7500_firmware | — | cpe:2.3:o:amd:radeon_pro_w7500_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_w6400_firmware | — | cpe:2.3:o:amd:radeon_pro_w6400_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_w6500m_firmware | — | cpe:2.3:o:amd:radeon_pro_w6500m_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_w6300m_firmware | — | cpe:2.3:o:amd:radeon_pro_w6300m_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_w5700x_firmware | — | cpe:2.3:o:amd:radeon_pro_w5700x_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_pro_w5500x_firmware | — | cpe:2.3:o:amd:radeon_pro_w5500x_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_7900xtx_firmware | — | cpe:2.3:o:amd:radeon_rx_7900xtx_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_7900xt_firmware | — | cpe:2.3:o:amd:radeon_rx_7900xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_7800xt_firmware | — | cpe:2.3:o:amd:radeon_rx_7800xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_7700xt_firmware | — | cpe:2.3:o:amd:radeon_rx_7700xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_7600xt_firmware | — | cpe:2.3:o:amd:radeon_rx_7600xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_7600_firmware | — | cpe:2.3:o:amd:radeon_rx_7600_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_6950xt_firmware | — | cpe:2.3:o:amd:radeon_rx_6950xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_6900xt_firmware | — | cpe:2.3:o:amd:radeon_rx_6900xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_6800xt_firmware | — | cpe:2.3:o:amd:radeon_rx_6800xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_6800_firmware | — | cpe:2.3:o:amd:radeon_rx_6800_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5300m_firmware | — | cpe:2.3:o:amd:radeon_rx_5300m_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5300_firmware | — | cpe:2.3:o:amd:radeon_rx_5300_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5300xt_firmware | — | cpe:2.3:o:amd:radeon_rx_5300xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5500m_firmware | — | cpe:2.3:o:amd:radeon_rx_5500m_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5500_firmware | — | cpe:2.3:o:amd:radeon_rx_5500_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5500xt_firmware | — | cpe:2.3:o:amd:radeon_rx_5500xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5600m_firmware | — | cpe:2.3:o:amd:radeon_rx_5600m_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5600_firmware | — | cpe:2.3:o:amd:radeon_rx_5600_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5600xt_firmware | — | cpe:2.3:o:amd:radeon_rx_5600xt_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5700m_firmware | — | cpe:2.3:o:amd:radeon_rx_5700m_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5700_firmware | — | cpe:2.3:o:amd:radeon_rx_5700_firmware:-:*:*:*:*:*:*:* |
| amd | radeon_rx_5700xt_firmware | — | cpe:2.3:o:amd:radeon_rx_5700xt_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_9_7945hx3d_firmware | — | cpe:2.3:o:amd:ryzen_9_7945hx3d_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_9_7945hx_firmware | — | cpe:2.3:o:amd:ryzen_9_7945hx_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_9_7845hx_firmware | — | cpe:2.3:o:amd:ryzen_9_7845hx_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_7745hx_firmware | — | cpe:2.3:o:amd:ryzen_7_7745hx_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_7645hx_firmware | — | cpe:2.3:o:amd:ryzen_5_7645hx_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_9_7940h_firmware | — | cpe:2.3:o:amd:ryzen_9_7940h_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_9_pro_7945hs_firmware | — | cpe:2.3:o:amd:ryzen_9_pro_7945hs_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_pro_7840hs_firmware | — | cpe:2.3:o:amd:ryzen_7_pro_7840hs_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_7840h_firmware | — | cpe:2.3:o:amd:ryzen_7_7840h_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_pro_7840u_firmware | — | cpe:2.3:o:amd:ryzen_7_pro_7840u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_7640hs_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_7640hs_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_7640h_firmware | — | cpe:2.3:o:amd:ryzen_5_7640h_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_7640u_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_7640u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_7545u_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_7545u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_7540u_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_7540u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_7440u_firmware | — | cpe:2.3:o:amd:ryzen_3_7440u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_5700g_firmware | — | cpe:2.3:o:amd:ryzen_7_5700g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_5700ge_firmware | — | cpe:2.3:o:amd:ryzen_7_5700ge_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_5600gt_firmware | — | cpe:2.3:o:amd:ryzen_5_5600gt_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_5600g_firmware | — | cpe:2.3:o:amd:ryzen_5_5600g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_5600ge_firmware | — | cpe:2.3:o:amd:ryzen_5_5600ge_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_5500gt_firmware | — | cpe:2.3:o:amd:ryzen_5_5500gt_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_5300g_firmware | — | cpe:2.3:o:amd:ryzen_3_5300g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_5300ge_firmware | — | cpe:2.3:o:amd:ryzen_3_5300ge_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_3400g_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_3400g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_3400g_firmware | — | cpe:2.3:o:amd:ryzen_5_3400g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_3400ge_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_3400ge_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_3350g_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_3350g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_pro_3350ge_firmware | — | cpe:2.3:o:amd:ryzen_5_pro_3350ge_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_pro_3200g_firmware | — | cpe:2.3:o:amd:ryzen_3_pro_3200g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_3200g_firmware | — | cpe:2.3:o:amd:ryzen_3_3200g_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_3200ge_firmware | — | cpe:2.3:o:amd:ryzen_3_3200ge_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_pro_3200ge_firmware | — | cpe:2.3:o:amd:ryzen_3_pro_3200ge_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_7735hs_firmware | — | cpe:2.3:o:amd:ryzen_7_7735hs_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_7736u_firmware | — | cpe:2.3:o:amd:ryzen_7_7736u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_7_7735u_firmware | — | cpe:2.3:o:amd:ryzen_7_7735u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_7535hs_firmware | — | cpe:2.3:o:amd:ryzen_5_7535hs_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_5_7535u_firmware | — | cpe:2.3:o:amd:ryzen_5_7535u_firmware:-:*:*:*:*:*:*:* |
| amd | ryzen_3_7335u_firmware | — | cpe:2.3:o:amd:ryzen_3_7335u_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://blog.trailofbits.com | Exploit Mitigation Third Party Advisory |
| https://kb.cert.org/vuls/id/446598 | Third Party Advisory US Government Resource |
| https://registry.khronos.org/OpenCL/specs/3.0-unified/html/OpenCL_API.html#_fundamental_memory_regions | Technical Description |
| https://registry.khronos.org/vulkan/specs/1.3-extensions/html/index.html | Vendor Advisory |
| https://www.kb.cert.org/vuls/id/446598 | Third Party Advisory US Government Resource |