Impact
The vulnerability is a use‑after‑free condition in the Mali GPU kernel driver. A local non‑privileged user can trigger improper GPU memory operations that read memory that has already been freed. Based on the description, it is inferred that the victim can observe residual data on the GPU device—information that may have come from another process or from sensitive data previously handled by the GPU. The weakness maps to CWE‑416 and represents a classic memory violation that can lead to data disclosure.
Affected Systems
The flaw is present in Bifrost GPU Kernel Driver (versions r49p3 to r49p5, r51p0, r54p1 to r54p2), the Valhall GPU Kernel Driver (versions r49p3 to r49p5, r51p0 to r54p3, r55p0), and the Arm 5th Gen GPU Architecture Kernel Driver (versions r49p3 to r49p5, r51p0 to r54p3, r55p0). All versions below r56p0 lack the patch that resolves the memory safety issue.
Risk and Exploitability
The risk is localized to any user with a process that can invoke the GPU driver. There is no evidence that the flaw grants elevation of privilege or remote execution capabilities. The CVSS score of 7.8 indicates moderate to high impact, and the EPSS score is < 1% while the CVE is not listed in CISA's KEV catalog, suggesting that exploitation is not widespread or actively observed. Based on the description, it is inferred that reading arbitrary freed memory can leak confidential data, so the severity warrants immediate attention. Attackers would need local access to trigger the driver routines, and the exploit path requires calling a specific GPU command sequence that accesses freed buffer memory.
OpenCVE Enrichment