CVE-2025-1246: Mali GPU Userspace Driver allows an Out-of-Bounds access
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r18p0 through r49p3, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r28p0 through r49p3, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p3, from r50p0 through r54p0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arm Ltd Bifrost GPU Userspace Driverto a version that resolves this vulnerability.Fixed in r49p4 - Upgrade
Upgrade
Arm Ltd Bifrost GPU Userspace Driverto a version that resolves this vulnerability.Fixed in r54p1 - Upgrade
Upgrade
Arm Ltd Valhall GPU Userspace Driverto a version that resolves this vulnerability.Fixed in r49p4 - Upgrade
Upgrade
Arm Ltd Valhall GPU Userspace Driverto a version that resolves this vulnerability.Fixed in r54p1 - Upgrade
Upgrade
Arm 5th Gen GPU Architecture Userspace Driverto a version that resolves this vulnerability.Fixed in r49p4 - Upgrade
Upgrade
Arm 5th Gen GPU Architecture Userspace Driverto a version that resolves this vulnerability.Fixed in r54p1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1246?
The severity of CVE-2025-1246 is considered high, as it allows a non-privileged user to manipulate GPU processes.
How do I fix CVE-2025-1246?
To fix CVE-2025-1246, update the affected Arm GPU Userspace Drivers to the latest patched versions.
Which software is affected by CVE-2025-1246?
CVE-2025-1246 affects the Arm Bifrost, Valhall, and 5th Gen GPU Userspace Drivers within specific version ranges.
What causes the vulnerability CVE-2025-1246?
CVE-2025-1246 is caused by improper restriction of operations within the bounds of a memory buffer.
Can CVE-2025-1246 be exploited remotely?
CVE-2025-1246 requires local access to the system, making remote exploitation unlikely without prior compromise.