Impact
The vulnerability is a use‑after‑free flaw in the GPU kernel driver, allowing a local non‑privileged process to trigger GPU memory operations that read data already freed. This can expose sensitive information that should no longer be retrievable or corrupt system memory when the driver later accesses it. The weakness, labeled as CWE‑416, shows that memory safety is breached, potentially leading to data leakage or system instability.
Affected Systems
The flaw affects Arm Ltd’s GPU kernel drivers for its 5th Gen Architecture, Bifrost, and Valhall GPUs. Affected releases for Bifrost include r41p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p2. Valhall drivers from r41p0 through r49p5, r50p0 through r54p3, and r55p0 are vulnerable. The Arm 5th Gen Architecture Kernel Driver is affected for r41p0 through r49p5, r50p0 through r54p3, and r55p0. Arm has addressed the issue in r56p0 for both Valhall and the 5th Gen Architecture, while Bifrost support for the update should be confirmed through vendor coordination.
Risk and Exploitability
The attack requires a local user context and does not grant elevated privileges, so the impact is confined to the target host. No evidence of remote exploitation or hypervisor breakout is reported. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. With a CVSS score of 4.4, the severity is moderate, but the potential for data leakage or process crashes makes the risk noteworthy for systems relying on GPU acceleration.
OpenCVE Enrichment