Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to sensitive kernel information.



This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
Published: 2026-09-08
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when a local, non‑privileged user can trigger GPU memory operations that expose kernel memory contents written by the driver. This allows the user to read confidential kernel data, resulting in a breach of confidentiality. The weakness is a classic information disclosure flaw classified as CWE‑200.

Affected Systems

The flaw is present in two families of Arm Ltd GPU kernel drivers: the Valhall GPU Kernel Driver and the Arm 5th Gen GPU Architecture Kernel Driver. Affected releases span r29p0 through r49p5, r50p0 through r54p3, and r55p0 for Valhall, and r41p0 through r49p5, r50p0 through r54p3, and r55p0 for the 5th Gen driver.

Risk and Exploitability

The CVE lacks an official CVSS score and the EPSS value is not available, so a numeric severity cannot be quoted. However, because the vulnerability allows a local user to read kernel‑level data, the potential impact on confidentiality is significant. The problem can be exploited by any local non‑privileged process that uses the driver, without additional privilege escalation steps. No public exploits are reported and it is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 8, 2026 at 15:30 UTC.

Remediation

Vendor Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver: r56p0; Arm 5th Gen GPU Architecture Kernel Driver: r56p0. Arm partners are recommended to upgrade to the latest applicable version as soon as possible.


OpenCVE Recommended Actions

  • Update the driver to version r56p0 or later, which contains the patch.
  • If the update cannot be applied immediately, contact Arm support or the relevant ARM partner to expedite the update or receive guidance.
  • As a temporary measure, limit local non‑privileged processes from accessing the GPU for sensitive workloads, or enforce stricter sandboxing of GPU memory access to mitigate the information disclosure.

Generated by OpenCVE AI on September 8, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to sensitive kernel information. This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
Title Mali GPU Kernel Driver allows access to sensitive kernel information
Weaknesses CWE-200
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2026-09-08T14:19:22.205Z

Reserved: 2026-01-12T13:44:43.992Z

Link: CVE-2026-0860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:39.953

Modified: 2026-09-08T15:24:07.790

Link: CVE-2026-0860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:30:18Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor