Description
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory.



This issue affects Bifrost GPU Kernel Driver: from r49p3 through r49p5, r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local data disclosure via use‑after‑free
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free condition in the Mali GPU kernel driver. A local non‑privileged user can trigger improper GPU memory operations that read memory that has already been freed. Based on the description, it is inferred that the victim can observe residual data on the GPU device—information that may have come from another process or from sensitive data previously handled by the GPU. The weakness maps to CWE‑416 and represents a classic memory violation that can lead to data disclosure.

Affected Systems

The flaw is present in Bifrost GPU Kernel Driver (versions r49p3 to r49p5, r51p0, r54p1 to r54p2), the Valhall GPU Kernel Driver (versions r49p3 to r49p5, r51p0 to r54p3, r55p0), and the Arm 5th Gen GPU Architecture Kernel Driver (versions r49p3 to r49p5, r51p0 to r54p3, r55p0). All versions below r56p0 lack the patch that resolves the memory safety issue.

Risk and Exploitability

The risk is localized to any user with a process that can invoke the GPU driver. There is no evidence that the flaw grants elevation of privilege or remote execution capabilities. The CVSS score of 7.8 indicates moderate to high impact, and the EPSS score is < 1% while the CVE is not listed in CISA's KEV catalog, suggesting that exploitation is not widespread or actively observed. Based on the description, it is inferred that reading arbitrary freed memory can leak confidential data, so the severity warrants immediate attention. Attackers would need local access to trigger the driver routines, and the exploit path requires calling a specific GPU command sequence that accesses freed buffer memory.

Generated by OpenCVE AI on September 11, 2026 at 06:31 UTC.

Remediation

Vendor Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver: r56p0; Arm 5th Gen GPU Architecture Kernel Driver: r56p0. Arm partners are recommended to upgrade to the latest applicable version as soon as possible.


OpenCVE Recommended Actions

  • Upgrade Valhall GPU Kernel Driver to version r56p0 or later.
  • Upgrade Arm 5th Gen GPU Architecture Kernel Driver to version r56p0 or later.
  • Check for and install the latest Bifrost GPU Kernel Driver patch from Arm’s support portal; apply when released.

Generated by OpenCVE AI on September 11, 2026 at 06:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver
Vendors & Products Arm
Arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r49p3 through r49p5, r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0.
Title Mali GPU Kernel Driver allows access to already freed memory
Weaknesses CWE-416
References

Subscriptions

Arm 5th Gen Gpu Architecture Kernel Driver Bifrost Gpu Kernel Driver Valhall Gpu Kernel Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2026-09-10T18:14:26.053Z

Reserved: 2026-04-29T22:12:10.791Z

Link: CVE-2026-7476

cve-icon Vulnrichment

Updated: 2026-09-10T18:14:17.421Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:48.773

Modified: 2026-09-10T19:17:35.223

Link: CVE-2026-7476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:45:06Z

Weaknesses