Use After Free Vulnerability in Arm Ltd Valhall GPU Kernel Driver
CVE-2025-6349

5.1MEDIUM

What is CVE-2025-6349?

A Use After Free vulnerability exists in the Arm Ltd Valhall GPU Kernel Driver, which allows a local non-privileged user to exploit improper memory operations. This flaw could enable attackers to gain unauthorized access to freed GPU memory, posing a significant risk to system integrity. The vulnerability affects versions of the Valhall GPU Kernel Driver in the range from r53p0 through r54p1, as well as the Arm 5th Gen GPU Architecture Kernel Driver in the same version range, highlighting the need for immediate attention and remediation strategies.

Affected Version(s)

Arm 5th Gen GPU Architecture Kernel Driver r53p0

Valhall GPU Kernel Driver r53p0

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pumpkin (@u1f383) from DEVCORE Research Team
.