PT-2024-5074 · Arm · Arm Bifrost Gpu Kernel Driver+2

Published

2024-04-19

·

Updated

2026-06-11

·

CVE-2024-1065

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Arm Ltd Bifrost GPU Kernel Driver versions r45p0 through r48p0 Arm Ltd Valhall GPU Kernel Driver versions r45p0 through r48p0 Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r45p0 through r48p0
Description: The issue is related to a Use After Free vulnerability in the kernel drivers for Arm-based Mali graphics processors, specifically those using Bifrost and Valhall architectures. This vulnerability is caused by synchronization errors when accessing shared resources. Exploitation of this issue may allow an attacker to execute arbitrary code. A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
Recommendations: For Arm Ltd Bifrost GPU Kernel Driver versions r45p0 through r48p0, update to a version outside of this range to resolve the issue. For Arm Ltd Valhall GPU Kernel Driver versions r45p0 through r48p0, update to a version outside of this range to resolve the issue. For Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r45p0 through r48p0, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the GPU memory processing operations to minimize the risk of exploitation.

Fix

Use After Free

Weakness Enumeration

Related Identifiers

ASB-A-329096276
BDU:2024-05601
CVE-2024-1065

Affected Products

Arm 5Th Gen Gpu Architecture Kernel Driver
Arm Bifrost Gpu Kernel Driver
Arm Valhall Gpu Kernel Driver