First published: Fri May 02 2025(Updated: )
Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory. This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p3, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p3, from r50p0 through r53p0.
Credit: arm-security@arm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arm Ltd Valhall GPU Kernel Driver | >=r29p0<=r49p3>=r50p0<=r53p0 | |
Arm 5th Gen GPU Architecture Kernel Driver | >=r41p0<=r49p3>=r50p0<=r53p0 |
This issue has been fixed in the following versions: Valhall GPU Kernel Driver r49p4 and r54p0; Arm 5th Gen GPU Architecture Kernel Driver r49p4, r54p0. Arm recommends that affected users upgrade to the latest applicable version at Mali Driver Downloads to protect against this issue.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0072 is a medium-severity vulnerability that allows improper GPU memory processing operations.
To fix CVE-2025-0072, update the Arm Valhall GPU Kernel Driver or the Arm 5th Gen GPU Architecture Kernel Driver to a patched version.
CVE-2025-0072 affects local non-privileged user processes using the affected versions of the Arm GPU drivers.
CVE-2025-0072 is classified as a Use After Free vulnerability, which can potentially allow access to freed memory.
CVE-2025-0072 affects Arm Valhall GPU Kernel Driver versions from r29p0 to r49p3 and versions from r50p0 to r53p0.