Description
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory.



This issue affects Bifrost GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p3; Valhall GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free memory disclosure
Action: Patch Now
AI Analysis

Impact

Arm Ltd’s Mali GPU user‑space drivers contain a use‑after‑free flaw that allows a non‑privileged, local user process to issue legitimate GPU operations, such as through WebGL or WebGPU. The flaw enables the process to read data that has already been freed from memory, exposing the contents of a released buffer. The primary consequence is the disclosure of confidential information that was once stored in system or process memory.

Affected Systems

Affected drivers include Arm Ltd’s Bifrost, Valhall, and 5th‑Gen GPU Architecture user‑space drivers. Vulnerable releases span r42p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p3 for all three families; Valhall and the 5th‑Gen families also include r55p0 as a vulnerable release. The latest fixed versions are Valhall GPU Userspace Driver r56p0 and Arm 5th‑Gen GPU Architecture Userspace Driver r56p0.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation. Attackers need only local user credentials, and they can trigger the flaw by performing normal GPU rendering tasks; privilege escalation is not required, a fact inferred from the description. Thus the risk is confined to local environments where untrusted code may execute GPU operations.

Generated by OpenCVE AI on September 11, 2026 at 06:30 UTC.

Remediation

Vendor Solution

This issue has been fixed in the following versions: Valhall GPU Userspace Driver: r56p0; Arm 5th Gen GPU Architecture Userspace Driver: r56p0. Arm partners are recommended to upgrade to the latest applicable version as soon as possible.


OpenCVE Recommended Actions

  • Upgrade Valhall and 5th‑Gen GPU Architecture drivers to r56p0 or later, as those releases contain the fix.
  • If the system uses the Bifrost driver, check with Arm or the relevant partner for a patched version; if a fixed release exists, apply it promptly.
  • After updating the driver, reboot the system or restart the GPU driver service to ensure the patched driver is loaded.

Generated by OpenCVE AI on September 11, 2026 at 06:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Arm
Arm 5th Gen Gpu Architecture Userspace Driver
Arm bifrost Gpu Userspace Driver
Arm valhall Gpu Userspace Driver
Vendors & Products Arm
Arm 5th Gen Gpu Architecture Userspace Driver
Arm bifrost Gpu Userspace Driver
Arm valhall Gpu Userspace Driver

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory. This issue affects Bifrost GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p3; Valhall GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0.
Title Mali GPU Userspace Driver allows access to already freed memory
Weaknesses CWE-416
References

Subscriptions

Arm 5th Gen Gpu Architecture Userspace Driver Bifrost Gpu Userspace Driver Valhall Gpu Userspace Driver
cve-icon MITRE

Status: PUBLISHED

Assigner: Arm

Published:

Updated: 2026-09-10T18:03:49.974Z

Reserved: 2026-05-19T16:30:46.525Z

Link: CVE-2026-9034

cve-icon Vulnrichment

Updated: 2026-09-10T18:03:40.299Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T15:18:56.353

Modified: 2026-09-10T19:17:42.527

Link: CVE-2026-9034

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:45:06Z

Weaknesses