Impact
The vulnerability arises when a local, non‑privileged user can trigger GPU memory operations that expose kernel memory contents written by the driver. This allows the user to read confidential kernel data, resulting in a breach of confidentiality. The weakness is a classic information disclosure flaw classified as CWE‑200.
Affected Systems
The flaw is present in two families of Arm Ltd GPU kernel drivers: the Valhall GPU Kernel Driver and the Arm 5th Gen GPU Architecture Kernel Driver. Affected releases span r29p0 through r49p5, r50p0 through r54p3, and r55p0 for Valhall, and r41p0 through r49p5, r50p0 through r54p3, and r55p0 for the 5th Gen driver.
Risk and Exploitability
The CVE lacks an official CVSS score and the EPSS value is not available, so a numeric severity cannot be quoted. However, because the vulnerability allows a local user to read kernel‑level data, the potential impact on confidentiality is significant. The problem can be exploited by any local non‑privileged process that uses the driver, without additional privilege escalation steps. No public exploits are reported and it is not listed in the CISA KEV catalog.
OpenCVE Enrichment