CVE-2025-0427

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r8p0 through r49p3, from r50p0 through r51p0; Valhall GPU Kernel Driver: from r19p0 through r49p3, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p3, from r50p0 through r53p0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ArmCNA
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
VendorProductVersion
arm5th_gen_gpu_architecture_kernel_driver
r41p0 ≤
𝑥
≤ r49p3
arm5th_gen_gpu_architecture_kernel_driver
r50p0 ≤
𝑥
≤ r53p0
armbifrost_gpu_kernel_driver
r8p0 ≤
𝑥
≤ r49p3
armbifrost_gpu_kernel_driver
r50p0 ≤
𝑥
≤ r51p0
armvalhall_gpu_kernel_driver
r19p0 ≤
𝑥
≤ r49p3
armvalhall_gpu_kernel_driver
r50p0 ≤
𝑥
≤ r53p0
𝑥
= Vulnerable software versions