Impact
A use‑after‑free flaw in Arm’s Bifrost, Valhall, and 5th‑Gen GPU kernel drivers lets a local non‑privileged user perform GPU memory operations on memory that has already been freed, allowing the attacker to read arbitrary data that may have resided in GPU buffers. This vulnerability does not provide a path to code execution or privilege escalation but can leak sensitive user or application data, constituting an information disclosure flaw (CWE‑416).
Affected Systems
The flaw affects Arm Ltd Bifrost GPU Kernel Driver releases r41p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p2, and Arm Ltd Valhall GPU Kernel Driver releases r41p0 through r49p5, r50p0 through r54p3, and r55p0, as well as Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver releases r41p0 through r49p5, r50p0 through r54p3, and r55p0. The vendor has published fixes for Valhall and the 5th‑Gen Architecture driver in release r56p0; a patch for Bifrost has not been explicitly released, so systems running any affected Bifrost version remain vulnerable unless updated by Arm partners.
Risk and Exploitability
The attack requires local access to submit GPU jobs and is limited to a user with no elevated privileges. The EPSS score of <1% indicates a very low probability of exploitation, and the CVSS score of 4 classifies the issue as low severity. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits. Nonetheless, because the flaw enables reading of freed GPU buffers, a local attacker may leak sensitive data, warranting prompt remediation.
OpenCVE Enrichment