Impact
A local non‑privileged user can invoke the Mali GPU kernel driver to perform valid GPU operations after memory has already been freed. Based on the description, this access may allow the user to read memory that could contain sensitive data. The flaw is a use‑after‑free condition (CWE‑416) that can result in information disclosure and potentially data corruption if the attacker can.
Affected Systems
The vulnerability affects the Valhall GPU Kernel Driver from r50p0 through r54p3 and r55p0, and the Arm 5th Gen GPU Architecture Kernel Driver from r50p0 through r54p3 and r55p0.
Risk and Exploitability
The flaw remains exploitable only by a local, non‑privileged process that has access to the Mali GPU driver. The CVSS score of 7.8 indicates high severity. The EPSS score of <1% shows the likelihood of exploitation is very low, and the vulnerability is not listed in CISA KEV. Thus the overall risk is moderate, with the primary concern being potential leakage of memory contents from freed kernel buffers.
OpenCVE Enrichment