7.8
CVSSv3

CVE-2025-0072

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00017 | KEV: Not Included
Published: 02/05/2025 Updated: 12/05/2025

Vulnerability Summary

Use After Free Vulnerability in Arm GPU Kernel Drivers Enabling Local Memory Manipulation

A Use After Free vulnerability exists in the Arm Ltd Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver. This security issue allows a local non-privileged user process to improperly process GPU memory operations and gain access to previously freed memory. The vulnerability impacts specific versions of the Valhall GPU Kernel Driver, including versions r29p0 through r49p3 and r50p0 through r53p0, as well as the Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r49p3 and r50p0 through r53p0.

Solution

This issue has been fixed in the following versions: Valhall GPU Kernel Driver r49p4 and r54p0; Arm 5th Gen GPU Architecture Kernel Driver r49p4, r54p0. Arm recommends that affected users upgrade to the latest applicable version at Mali Driver Downloads to protect against this issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm ltd valhall gpu kernel driver

arm ltd arm 5th gen gpu architecture kernel driver

arm 5th gen gpu architecture kernel driver

arm valhall gpu kernel driver