Executive brief
Arm's GPU kernel drivers for Bifrost, Valhall, and 5th Gen architectures contain a race condition that allows a local user to misuse GPU memory operations. An attacker can exploit this to crash the GPU subsystem (denial of service) or leak sensitive data from GPU memory, potentially exposing cryptographic keys, user data, or other confidential information stored in graphics memory.
Technical details
A race condition exists in the GPU memory processing logic of three Arm kernel drivers: Bifrost, Valhall, and 5th Gen GPU Architecture drivers. The vulnerability allows a local non-privileged process to perform improper GPU memory operations without proper synchronization or access controls. An attacker with local code execution can trigger the race condition to cause denial of service or read sensitive information from GPU memory. The vulnerability affects multiple versions: Bifrost r12p0–r49p5, r50p0–r51p0, r54p1–r54p2; Valhall r19p0–r49p5, r50p0–r54p3, r55p0; and 5th Gen r41p0–r49p5, r50p0–r54p3, r55p0. Patches are available in later versions of each driver.
Affected products
- Arm Bifrost GPU Kernel Driver r12p0 through r49p5, r50p0 through r51p0, r54p1 through r54p2
- Arm Valhall GPU Kernel Driver r19p0 through r49p5, r50p0 through r54p3, r55p0
- Arm 5th Gen GPU Architecture Kernel Driver r41p0 through r49p5, r50p0 through r54p3, r55p0
Timeline
- 2026-09-08: disclosed: Vulnerability published on NVD