Description
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory.



This issue affects Bifrost GPU Kernel Driver: from r44p0 through r49p4, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3, r55p0.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use After Free leading to memory disclosure
Action: Patch
AI Analysis

Impact

This vulnerability is a Use After Free flaw (CWE‑416) in the kernel code of Arm Ltd’s Bifrost, Valhall, and 5th Generation GPU Architecture drivers. A local, non‑privileged user can issue valid GPU memory processing commands that read data that has already been freed. The consequence is the disclosure of confidential information that was residing in GPU memory; the flaw does not give the attacker code execution or privilege escalation within the host.

Affected Systems

Affected drivers are Arm Ltd:Arm 5th Gen GPU Architecture Kernel Driver, Arm Ltd:Bifrost GPU Kernel Driver, and Arm Ltd:Valhall GPU Kernel Driver. The vulnerable releases include Bifrost from r44p0–r49p4, r50p0–r51p0, and r54p1–r54p2; Valhall from r44p0–r49p5, r50p0–r54p3; and the 5th Gen Architecture from r44p0–r49p5, r50p0–r54p3, and r55p0.

Risk and Exploitability

The CVSS score of 7.8 reflects a high‑severity local flaw. Because it requires the attacker to be a non‑privileged user with GPU access, it is not readily exploitable over the network. The EPSS score of < 1% indicates a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, so no known mass‑exploitation activity has been reported. The risk remains significant for systems that expose GPU functionality to untrusted processes, as the memory disclosure could be leveraged in further attacks.

Generated by OpenCVE AI on September 11, 2026 at 06:30 UTC.

Remediation

Vendor Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver: r56p0; Arm 5th Gen GPU Architecture Kernel Driver: r56p0. Arm partners are recommended to upgrade to the latest applicable version as soon as possible.


OpenCVE Recommended Actions

  • Upgrade the Valhall and 5th Generation GPU Architecture kernel drivers to version r56p0 or newer. For Bifrost, upgrade to the latest driver available from Arm, although no specific fixed version is documented.
  • If an immediate upgrade is not possible, disable or restrict GPU memory allocation for untrusted or non‑privileged processes by configuring the driver or applying system controls to limit GPU access.
  • Monitor system logs for anomalous GPU activity or unusual memory access patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on September 11, 2026 at 06:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver
Vendors & Products Arm
Arm 5th Gen Gpu Architecture Kernel Driver
Arm bifrost Gpu Kernel Driver
Arm valhall Gpu Kernel Driver

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r44p0 through r49p4, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3, r55p0.
Title Mali GPU Kernel Driver allows access to already freed memory
Weaknesses CWE-416
References

Subscriptions

Arm 5th Gen Gpu Architecture Kernel Driver Bifrost Gpu Kernel Driver Valhall Gpu Kernel Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2026-09-10T18:05:00.171Z

Reserved: 2026-04-29T22:26:00.556Z

Link: CVE-2026-7477

cve-icon Vulnrichment

Updated: 2026-09-10T18:04:57.206Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:48.873

Modified: 2026-09-10T19:17:35.373

Link: CVE-2026-7477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:45:06Z

Weaknesses