Description
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory.



This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
Published: 2026-09-08
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the GPU kernel driver, allowing a local non‑privileged process to trigger GPU memory operations that read data already freed. This can expose sensitive information that should no longer be retrievable or corrupt system memory when the driver later accesses it. The weakness, labeled as CWE‑416, shows that memory safety is breached, potentially leading to data leakage or system instability.

Affected Systems

The flaw affects Arm Ltd’s GPU kernel drivers for its 5th Gen Architecture, Bifrost, and Valhall GPUs. Affected releases for Bifrost include r41p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p2. Valhall drivers from r41p0 through r49p5, r50p0 through r54p3, and r55p0 are vulnerable. The Arm 5th Gen Architecture Kernel Driver is affected for r41p0 through r49p5, r50p0 through r54p3, and r55p0. Arm has addressed the issue in r56p0 for both Valhall and the 5th Gen Architecture, while Bifrost support for the update should be confirmed through vendor coordination.

Risk and Exploitability

The attack requires a local user context and does not grant elevated privileges, so the impact is confined to the target host. No evidence of remote exploitation or hypervisor breakout is reported. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. With a CVSS score of 4.4, the severity is moderate, but the potential for data leakage or process crashes makes the risk noteworthy for systems relying on GPU acceleration.

Generated by OpenCVE AI on September 8, 2026 at 16:29 UTC.

Remediation

Vendor Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver: r56p0; Arm 5th Gen GPU Architecture Kernel Driver: r56p0. Arm partners are recommended to upgrade to the latest applicable version as soon as possible.


OpenCVE Recommended Actions

  • Upgrade the Arm GPU kernel drivers to r56p0 or newer for Valhall and ARM 5th Gen as recommended by Arm.
  • If a recent driver update for Bifrost is not yet released, coordinate with OEM or Android partners to confirm the latest supported version and apply it when available.
  • For devices that cannot be upgraded immediately, disable GPU acceleration in critical applications until the driver patch becomes available.

Generated by OpenCVE AI on September 8, 2026 at 16:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver
Vendors & Products Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
Title Mali GPU Kernel Driver allows access to already freed memory
Weaknesses CWE-416
References

Subscriptions

Arm Arm 5th Gen Gpu Architecture Kernel Driver Bifrost Gpu Kernel Driver Valhall Gpu Kernel Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2026-09-08T14:36:37.191Z

Reserved: 2025-10-09T10:18:31.149Z

Link: CVE-2026-0001

cve-icon Vulnrichment

Updated: 2026-09-08T14:36:20.835Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:39.773

Modified: 2026-09-08T15:24:07.790

Link: CVE-2026-0001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:30:17Z

Weaknesses