CVE-2026-9034: Mali GPU Userspace Driver allows access to already freed memory
Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access already freed memory.
This issue affects Bifrost GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p3; Valhall GPU Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Userspace Driver: from r42p0 through r49p5, from r50p0 through r54p3, r55p0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Valhall GPU Userspace Driverto a version that resolves this vulnerability.Fixed in r56p0 - Upgrade
Upgrade
Arm 5th Gen GPU Architecture Userspace Driverto a version that resolves this vulnerability.Fixed in r56p0 - Compensating control
Mitigate exposure by preventing unprivileged processes from performing GPU processing operations (e.g., via WebGL or WebGPU) until the GPU Userspace Driver is upgraded to the fixed versions.
Event History
Frequently Asked Questions
Who can exploit this issue?
A non-privileged user process can exploit the issue. The vulnerable GPU operations may be reached through WebGL or WebGPU, so exposure is not limited to native GPU applications.
Which driver releases are affected?
Bifrost is affected from r42p0 through r49p5, r50p0 through r51p0, and r54p1 through r54p3. Valhall and Arm 5th Gen GPU Architecture drivers are affected from r42p0 through r49p5, r50p0 through r54p3, and r55p0.
Does exploitation require invalid GPU commands or elevated privileges?
No. The issue can be triggered by a non-privileged process performing valid GPU processing operations.