CVE-2026-11891: Mali GPU Userspace Driver allows access to already freed memory
Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory.
This issue affects Valhall GPU Userspace Driver: from r46p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Userspace Driver: from r46p0 through r49p5, from r50p0 through r54p3, r55p0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Valhall GPU Userspace Driverto a version that resolves this vulnerability.Fixed in r56p0 - Upgrade
Upgrade
Arm 5th Gen GPU Architecture Userspace Driverto a version that resolves this vulnerability.Fixed in r56p0 - Compensating control
If upgrade to Valhall GPU Userspace Driver r56p0 / Arm 5th Gen GPU Architecture Userspace Driver r56p0 is not immediately possible, mitigate exposure by preventing non-privileged user process access to GPU processing operations (including via WebGL or WebGPU) until the fixed driver versions are deployed.
Event History
Frequently Asked Questions
Who can exploit this issue?
A non-privileged local user process can exploit it by performing valid GPU processing operations. The affected operations may be reached through WebGL or WebGPU.
Which driver releases are affected?
Affected Valhall and Arm 5th Gen GPU Architecture Userspace Driver releases are r46p0 through r49p5, r50p0 through r54p3, and r55p0.