Impact
This vulnerability is a Use After Free in the Mali GPU kernel drivers, allowing a local non‑privileged user process to trigger GPU memory operations that read memory that has already been freed. The consequence is that the attacker can read data that should have been deallocated, potentially leaking sensitive information stored in GPU memory. The flaw does not grant arbitrary code execution or system‑wide privilege escalation, but it does expose confidential data that could be leveraged in further attacks.
Affected Systems
Affected by Arm Ltd. The drivers impacted are the Bifrost GPU Kernel Driver, the Valhall GPU Kernel Driver, and the ARM 5th Generation GPU Architecture Kernel Driver. The vulnerable releases span driver revisions r44p0 through r49p5, r50p0 to r51p0 or r54p3, and for the 5th Gen also up to r55p0. The fix is available in r56p0 for the Valhall and 5th Gen drivers; Bifrost drivers are also advised to upgrade to the latest release available from Arm.
Risk and Exploitability
The issue is local to the host and requires a non‑privileged user to initiate GPU memory requests. Because it occurs in kernel code, the attack can expose data but does not provide privilege escalation. No CVSS score is listed here, and the EPSS score is not available, so the likelihood of widespread exploitation is uncertain; however, the risk can be significant if a system stores high‑value data in GPU memory. The vulnerability is not listed in the CISA KEV catalog, indicating no known mass exploitation.
OpenCVE Enrichment