Impact
A use‑after‑free flaw in Arm Ltd’s Valhall GPU Userspace Driver and 5th Gen GPU Architecture Userspace Driver allows any local, non‑priv WebGL or WebGPU requests, that accesses memory already freed. The driver then returns data from that deallocated region, enabling the attacker to read data that should no longer be available. This constitutes an unauthorized memory disclosure, providing a potential channel for leaking sensitive information. The weakness is classified as a classic CWE‑416 scenario and does not provide elevated privileges or remote execution.
Affected Systems
The vulnerability applies to the Valhall GPU Userspace Driver releases r46p0 through r49p5, r50p0 through r54p3, and r55p0, as well as the 5th Gen GPU Architecture Drivers covering identical version ranges. All other releases outside these ranges are not affected; the issue does not impact kernel‑space drivers or other Arm GPU components.
Risk and Exploitability
The likely attack vector is local, requiring a non‑privileged user able to inject GPU work. The EPSS score is below 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread attacks. The CVSS score of 5.1 classifies the flaw as moderate severity, reflecting the risk of unauthorized memory disclosure. The impact is significant for confidentiality, but the flaw does not provide privilege escalation or remote code execution.
OpenCVE Enrichment