Improper Memory Buffer Management in Arm's Bifrost and Valhall GPU Drivers
CVE-2025-1246
Key Information:
- Vendor
Arm
- Status
- Vendor
- CVE Published:
- 2 June 2025
What is CVE-2025-1246?
A vulnerability exists in Arm Ltd's Bifrost and Valhall GPU Userspace Drivers due to improper restriction of operations within memory buffer bounds, allowing non-privileged user processes to execute valid GPU operations, potentially leading to unauthorized access beyond intended buffer limits. This affects the Bifrost GPU Userspace Driver across several versions and the Valhall GPU Userspace Driver, enabling risks associated with unsafe memory access in applications utilizing WebGL or WebGPU technologies.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Arm 5th Gen GPU Architecture Userspace Driver r41p0
Arm 5th Gen GPU Architecture Userspace Driver r50p0
Bifrost GPU Userspace Driver r18p0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved