Impact
Arm Ltd’s Mali GPU user‑space drivers contain a use‑after‑free flaw that allows a non‑privileged, local user process to issue legitimate GPU operations, such as through WebGL or WebGPU. The flaw enables the process to read data that has already been freed from memory, exposing the contents of a released buffer. The primary consequence is the disclosure of confidential information that was once stored in system or process memory.
Affected Systems
Affected drivers include Arm Ltd’s Bifrost, Valhall, and 5th‑Gen GPU Architecture user‑space drivers. Vulnerable releases span r42p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p3 for all three families; Valhall and the 5th‑Gen families also include r55p0 as a vulnerable release. The latest fixed versions are Valhall GPU Userspace Driver r56p0 and Arm 5th‑Gen GPU Architecture Userspace Driver r56p0.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation. Attackers need only local user credentials, and they can trigger the flaw by performing normal GPU rendering tasks; privilege escalation is not required, a fact inferred from the description. Thus the risk is confined to local environments where untrusted code may execute GPU operations.
OpenCVE Enrichment