Impact
The vulnerability is a kernel‑level use‑after‑free that allows a local non‑privileged user process to perform valid GPU memory processing operations to access already freed memory. This can expose data that was previously allocated to the user or other processes, leading to confidential information leakage. The weakness is identified as CWE‑416.
Affected Systems
Arm Ltd produces several GPU kernel drivers affected by this flaw. The Bifrost GPU kernel driver versions r41p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p2 are vulnerable. For the Valhall GPU kernel driver, versions r41p0 through r49p5, r50p0 through r54p3, and r55p0 fall within the affected range. The 5th‑Generation GPU Architecture kernel driver is also impacted in versions r41p0 through r49p5, r50p0 through r54p3, and r55p0.
Risk and Exploitability
The vulnerability can be triggered by any local user with access to the GPU, as it requires only the ability to submit standard GPU memory operations. The EPSS score of 0.00139 indicates a negligible likelihood of exploitation, and it is not listed in the KEV catalog. Use‑after‑free defects in kernel drivers are generally regarded as high‑severity, but this vulnerability has a CVSS score of 5.1, indicating moderate risk and potentially enabling local information disclosure. The exploitation cost is relatively low, but it requires a local process and does not necessitate elevated privileges. Because the flaw affects kernel memory, the damage is confined to the victim, with no additional control over the driver. No public exploits have been reported, but the lack of a KEV listing does not preclude potential future exploitation.
OpenCVE Enrichment