Junglewise Threat Intelligence

CVE-2026-11891: Arm Valhall GPU Userspace Driver use-after-free vulnerability

CVE-2026-11891 · Severity: medium · CVSS 5.1 · Published 2026-09-08

Vendors: Arm.

Executive brief

Arm's Valhall GPU Userspace Driver contains a use-after-free vulnerability that allows an unprivileged user to access memory that has already been freed by the GPU. An attacker can trigger this flaw through normal GPU operations, including web-based graphics APIs like WebGL or WebGPU, potentially leading to information disclosure or denial of service.

Technical details

A use-after-free vulnerability exists in the Valhall GPU Userspace Driver's memory management logic. The vulnerability is triggered when a non-privileged user process performs valid GPU processing operations via WebGL or WebGPU interfaces, accessing memory regions that have already been deallocated. The flaw allows an attacker to read or corrupt freed memory without requiring elevated privileges or special system configuration. Arm has released patches addressing this issue across affected driver versions.

Affected products

  • Arm Valhall GPU Userspace Driver r46p0 through r49p5, r50p0 through r54p3, r55p0
  • Arm Arm 5th Gen GPU Architecture Userspace Driver r46p0 through r49p5, r50p0 through r54p3, r55p0

Timeline

  • 2026-09-08: disclosed

References

Related threats