Description
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory.



This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
Published: 2026-09-08
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local information disclosure via use‑after‑free
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a kernel‑level use‑after‑free that allows a local non‑privileged user process to perform valid GPU memory processing operations to access already freed memory. This can expose data that was previously allocated to the user or other processes, leading to confidential information leakage. The weakness is identified as CWE‑416.

Affected Systems

Arm Ltd produces several GPU kernel drivers affected by this flaw. The Bifrost GPU kernel driver versions r41p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p2 are vulnerable. For the Valhall GPU kernel driver, versions r41p0 through r49p5, r50p0 through r54p3, and r55p0 fall within the affected range. The 5th‑Generation GPU Architecture kernel driver is also impacted in versions r41p0 through r49p5, r50p0 through r54p3, and r55p0.

Risk and Exploitability

The vulnerability can be triggered by any local user with access to the GPU, as it requires only the ability to submit standard GPU memory operations. The EPSS score of 0.00139 indicates a negligible likelihood of exploitation, and it is not listed in the KEV catalog. Use‑after‑free defects in kernel drivers are generally regarded as high‑severity, but this vulnerability has a CVSS score of 5.1, indicating moderate risk and potentially enabling local information disclosure. The exploitation cost is relatively low, but it requires a local process and does not necessitate elevated privileges. Because the flaw affects kernel memory, the damage is confined to the victim, with no additional control over the driver. No public exploits have been reported, but the lack of a KEV listing does not preclude potential future exploitation.

Generated by OpenCVE AI on September 11, 2026 at 05:20 UTC.

Remediation

Vendor Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver: r56p0; Arm 5th Gen GPU Architecture Kernel Driver: r56p0. Arm partners are recommended to upgrade to the latest applicable version as soon as possible.


OpenCVE Recommended Actions

  • Upgrade Valhall GPU Kernel Driver to version r56p0 or later, which contains the fix for the use‑after‑free issue.
  • Upgrade Arm 5th Generation GPU Architecture Kernel Driver to version r56p0 or later to address the same vulnerability.
  • Verify the installed Bifrost GPU Kernel Driver release; if it is still within the affected version range, update to the latest release where the flaw is patched or contact Arm for an advisory. If a patch is not yet available, restrict GPU access to trusted processes or disable the driver for untrusted users.

Generated by OpenCVE AI on September 11, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver
Vendors & Products Arm
Arm arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
Title Mali GPU Kernel Driver allows access to already freed memory
Weaknesses CWE-416
References

Subscriptions

Arm Arm 5th Gen Gpu Architecture Kernel Driver Bifrost Gpu Kernel Driver Valhall Gpu Kernel Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2026-09-10T17:57:23.474Z

Reserved: 2026-06-16T11:40:06.387Z

Link: CVE-2026-12387

cve-icon Vulnrichment

Updated: 2026-09-10T17:57:14.915Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:40.277

Modified: 2026-09-10T18:17:54.947

Link: CVE-2026-12387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:30:15Z

Weaknesses