PT-2025-16016 · Tp Link+1 · Tp-Link Smart Hub+2

Published

2025-04-10

·

Updated

2026-01-26

·

CVE-2025-0072

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arm Ltd Valhall GPU Kernel Driver versions r29p0 through r53p0 Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r53p0 TP-Link Smart Hub versions prior to an unspecified fixed version
Description A Use After Free issue in the Arm Ltd Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations, gaining access to already freed memory. Additionally, a flaw in the TP-Link Smart Hub exposes users' Wi-Fi credentials.
Recommendations For Arm Ltd Valhall GPU Kernel Driver versions r29p0 through r53p0, update to a version outside of the affected range to resolve the issue. For Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r53p0, update to a version outside of the affected range to resolve the issue. For TP-Link Smart Hub, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ASB-A-391928904
CVE-2025-0072

Affected Products

Arm 5Th Gen Gpu Architecture Kernel Driver
Tp-Link Smart Hub
Valhall Gpu Kernel Driver