CVE-2024-4610: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.
Other sources
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver: from r34p0 through r40p0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arm Bifrost GPU Kernel Driverto a version that resolves this vulnerability.Fixed in r41p0 - Upgrade
Upgrade
Arm Valhall GPU Kernel Driverto a version that resolves this vulnerability.Fixed in r41p0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4610?
CVE-2024-4610 is classified as a medium severity vulnerability due to its potential for local exploitation by non-privileged users.
How do I fix CVE-2024-4610?
To remediate CVE-2024-4610, users should update the Arm Mali and Valhall GPU kernel drivers to the latest patched version.
What type of vulnerability is CVE-2024-4610?
CVE-2024-4610 is a use-after-free vulnerability that can lead to improper GPU memory processing.
Which software is affected by CVE-2024-4610?
CVE-2024-4610 affects the Arm Bifrost and Valhall GPU kernel drivers, particularly those within certain version ranges.
Can CVE-2024-4610 be exploited remotely?
CVE-2024-4610 cannot be exploited remotely as it requires local access by a non-privileged user.