Improper Memory Buffer Management in Arm's Bifrost and Valhall GPU Drivers
CVE-2025-1246

7.8HIGH

What is CVE-2025-1246?

A vulnerability exists in Arm Ltd's Bifrost and Valhall GPU Userspace Drivers due to improper restriction of operations within memory buffer bounds, allowing non-privileged user processes to execute valid GPU operations, potentially leading to unauthorized access beyond intended buffer limits. This affects the Bifrost GPU Userspace Driver across several versions and the Valhall GPU Userspace Driver, enabling risks associated with unsafe memory access in applications utilizing WebGL or WebGPU technologies.

Affected Version(s)

Arm 5th Gen GPU Architecture Userspace Driver r41p0

Arm 5th Gen GPU Architecture Userspace Driver r50p0

Bifrost GPU Userspace Driver r18p0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-1246 : Improper Memory Buffer Management in Arm's Bifrost and Valhall GPU Drivers