Junglewise Threat Intelligence

CVE-2026-0001: Arm GPU Kernel Driver use-after-free in memory processing

CVE-2026-0001 · Severity: medium · CVSS 4.4 · Published 2026-09-08

Technologies: Arm 5th Gen GPU Architecture Kernel Driver, Arm Valhall GPU Kernel Driver, Arm Bifrost GPU Kernel Driver. Vendors: Arm.

Executive brief

Arm's GPU kernel drivers (Bifrost, Valhall, and 5th Gen architectures) contain a use-after-free vulnerability in GPU memory processing that allows a local user to access memory that has already been freed. An attacker could exploit this to read sensitive data, crash the GPU, or potentially execute code with GPU privileges on mobile devices and embedded systems using these drivers.

Technical details

A use-after-free vulnerability exists in the GPU memory processing operations of Arm's kernel drivers across Bifrost, Valhall, and 5th Gen GPU architectures. The vulnerability allows a local non-privileged user process to trigger GPU memory operations that access already-freed memory regions. Attack preconditions require local access and the ability to invoke valid GPU processing operations. An attacker with these capabilities could read freed memory contents, cause denial of service through GPU crashes, or potentially achieve code execution depending on memory layout and exploitation techniques. Patches are available for affected driver versions.

Affected products

  • Arm Bifrost GPU Kernel Driver r41p0 through r49p5, r50p0 through r51p0, r54p1 through r54p2
  • Arm Valhall GPU Kernel Driver r41p0 through r49p5, r50p0 through r54p3, r55p0
  • Arm 5th Gen GPU Architecture Kernel Driver r41p0 through r49p5, r50p0 through r54p3, r55p0

Timeline

  • 2026-09-08: disclosed: CVE-2026-0001 published

References

Related threats