Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to expose sensitive data.This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p4, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p4, from r50p0 through r54p0.
Advisories

No advisories yet.

Fixes

Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver r49p5, r54p1, r55p0; Arm 5th Gen GPU Architecture Kernel Driver r49p5, r54p1, r55p0. Arm partners are recommended to upgrade to use the latest applicable version as soon as possible.


Workaround

No workaround given by the vendor.

History

Mon, 01 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm valhall Gpu Kernel Driver
Vendors & Products Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm valhall Gpu Kernel Driver

Mon, 01 Dec 2025 10:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU processing operations to expose sensitive data.This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p4, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p4, from r50p0 through r54p0.
Title Mali GPU Kernel Driver allows improper GPU processing operations
Weaknesses CWE-200
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2025-12-01T18:15:49.190Z

Reserved: 2025-03-27T18:06:06.545Z

Link: CVE-2025-2879

cve-icon Vulnrichment

Updated: 2025-12-01T18:14:19.153Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-12-01T11:15:46.437

Modified: 2025-12-01T19:15:50.240

Link: CVE-2025-2879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-01T15:17:49Z