Executive brief
Arm's GPU kernel drivers (used in mobile and embedded devices) contain a use-after-free vulnerability that allows a local user to access freed GPU memory through specially crafted GPU operations. An attacker with local access could potentially read sensitive data from GPU memory, crash the GPU driver, or execute code with kernel privileges, affecting device stability and security.
Technical details
This is a use-after-free vulnerability in GPU memory handling within three Arm kernel drivers: Bifrost, Valhall, and Arm 5th Gen GPU Architecture. A local non-privileged user process can craft valid GPU memory operations to reference and access memory regions that have already been freed, bypassing memory safety protections. The vulnerability affects multiple version ranges across all three drivers. Exploitation requires local access and the ability to submit GPU operations, but does not require elevated privileges. An attacker can read freed memory contents, potentially leaking sensitive kernel or GPU driver data, or trigger use-after-free conditions leading to kernel panic or code execution.
Affected products
- Arm Ltd Bifrost GPU Kernel Driver r44p0 through r49p4, r50p0 through r51p0, r54p1 through r54p2
- Arm Ltd Valhall GPU Kernel Driver r44p0 through r49p5, r50p0 through r54p3
- Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver r44p0 through r49p5, r50p0 through r54p3, r55p0
Timeline
- 2026-09-08: disclosed