PT-2024-4008 · Arm · Arm Mali Gpu Kernel Driver+2
Published
2024-06-07
·
Updated
2025-12-04
·
CVE-2024-4610
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Arm Mali GPU Kernel Driver versions r34p0 through r40p0
Valhall GPU Kernel Driver versions r34p0 through r40p0
Description:
The issue is related to a Use-After-Free vulnerability in the Arm Mali GPU Kernel Driver, which can allow a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. This can potentially enable an attacker to execute arbitrary code. The vulnerability is currently being exploited, putting millions of devices at risk.
Recommendations:
For Bifrost GPU Kernel Driver versions r34p0 through r40p0, update to a version outside of this range to resolve the issue.
For Valhall GPU Kernel Driver versions r34p0 through r40p0, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the GPU memory processing operations until a patch is available.
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm Mali Gpu Kernel Driver
Arm Bifrost Gpu Kernel Driver
Valhall Gpu Kernel Driver