Impact
A race condition in Arm’s Mali GPU kernel drivers enables a local, non‑privileged user to perform improper GPU memory operations. The flaw can crash the driver, potentially affecting the entire system, or expose data that was stored in GPU memory. The weakness is classified as CWE‑362, a synchronicity defect.
Affected Systems
The vulnerability affects Bifrost GPU Kernel Driver (r12p0–r49p5, r50p0–r51p0, r54p1–r54p2), Valhall GPU Kernel Driver (r19p0–r49p5, r50p0–r54p3, r55p0), and Arm 5th Gen GPU Architecture Kernel Driver (r41p0–r49p5, r50p0–r54p3, r55p0).
Risk and Exploitability
The CVSS score is 7.7 and EPSS is < 1%. The CVE is not listed in CISA KEV. Because the race can be triggered by any non‑privileged user process, the risk to devices remains high if the affected drivers are in use. The CNA solution fixes the issue in Valhall and 5th Gen drivers as of r56p0; Bifrost drivers will remain vulnerable until a subsequent patch is released. Thus, systems with Valhall or 5th Gen drivers can be protected by updating, whereas devices still running vulnerable Bifrost builds require interim mitigation.
OpenCVE Enrichment