Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r53p0 through r54p1; Arm 5th Gen GPU Architecture Kernel Driver: from r53p0 through r54p1.
Advisories

No advisories yet.

Fixes

Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver r54p2, r55p0; Arm 5th Gen GPU Architecture Kernel Driver r54p2, r55p0. Arm partners are recommended to upgrade to use the latest applicable version as soon as possible.


Workaround

No workaround given by the vendor.

History

Mon, 01 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm valhall Gpu Kernel Driver
Vendors & Products Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm valhall Gpu Kernel Driver

Mon, 01 Dec 2025 10:45:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r53p0 through r54p1; Arm 5th Gen GPU Architecture Kernel Driver: from r53p0 through r54p1.
Title Mali GPU Kernel Driver allows improper GPU memory processing operations
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2025-12-01T18:08:09.444Z

Reserved: 2025-06-19T12:28:01.919Z

Link: CVE-2025-6349

cve-icon Vulnrichment

Updated: 2025-12-01T18:07:54.296Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-12-01T11:15:48.563

Modified: 2025-12-01T18:16:05.570

Link: CVE-2025-6349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-01T15:17:54Z