Description
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory.



This issue affects Bifrost GPU Kernel Driver: from r44p0 through r49p4, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3, r55p0.
Published: 2026-09-08
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a Use After Free in the Mali GPU kernel drivers, allowing a local non‑privileged user process to trigger GPU memory operations that read memory that has already been freed. The consequence is that the attacker can read data that should have been deallocated, potentially leaking sensitive information stored in GPU memory. The flaw does not grant arbitrary code execution or system‑wide privilege escalation, but it does expose confidential data that could be leveraged in further attacks.

Affected Systems

Affected by Arm Ltd. The drivers impacted are the Bifrost GPU Kernel Driver, the Valhall GPU Kernel Driver, and the ARM 5th Generation GPU Architecture Kernel Driver. The vulnerable releases span driver revisions r44p0 through r49p5, r50p0 to r51p0 or r54p3, and for the 5th Gen also up to r55p0. The fix is available in r56p0 for the Valhall and 5th Gen drivers; Bifrost drivers are also advised to upgrade to the latest release available from Arm.

Risk and Exploitability

The issue is local to the host and requires a non‑privileged user to initiate GPU memory requests. Because it occurs in kernel code, the attack can expose data but does not provide privilege escalation. No CVSS score is listed here, and the EPSS score is not available, so the likelihood of widespread exploitation is uncertain; however, the risk can be significant if a system stores high‑value data in GPU memory. The vulnerability is not listed in the CISA KEV catalog, indicating no known mass exploitation.

Generated by OpenCVE AI on September 8, 2026 at 15:28 UTC.

Remediation

Vendor Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver: r56p0; Arm 5th Gen GPU Architecture Kernel Driver: r56p0. Arm partners are recommended to upgrade to the latest applicable version as soon as possible.


OpenCVE Recommended Actions

  • Upgrade the Mali GPU kernel drivers to the latest fixed release; for Valhall and the 5th Gen drivers, version r56p0 or newer is recommended.
  • If an immediate upgrade is not possible, disable or restrict GPU memory allocation for untrusted processes, for example by configuring the driver or using system controls to limit GPU access.
  • Monitor system logs for anomalous GPU activity or unusual memory access patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on September 8, 2026 at 15:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r44p0 through r49p4, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r49p5, from r50p0 through r54p3, r55p0.
Title Mali GPU Kernel Driver allows access to already freed memory
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2026-09-08T14:20:38.565Z

Reserved: 2026-04-29T22:26:00.556Z

Link: CVE-2026-7477

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:48.873

Modified: 2026-09-08T15:24:07.790

Link: CVE-2026-7477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:30:18Z

Weaknesses