PT-2025-16016 · Tp Link+1 · Tp-Link Smart Hub+2
Published
2025-04-10
·
Updated
2026-01-26
·
CVE-2025-0072
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Arm Ltd Valhall GPU Kernel Driver versions r29p0 through r53p0
Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r53p0
TP-Link Smart Hub versions prior to an unspecified fixed version
Description
A Use After Free issue in the Arm Ltd Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations, gaining access to already freed memory. Additionally, a flaw in the TP-Link Smart Hub exposes users' Wi-Fi credentials.
Recommendations
For Arm Ltd Valhall GPU Kernel Driver versions r29p0 through r53p0, update to a version outside of the affected range to resolve the issue.
For Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver versions r41p0 through r53p0, update to a version outside of the affected range to resolve the issue.
For TP-Link Smart Hub, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arm 5Th Gen Gpu Architecture Kernel Driver
Tp-Link Smart Hub
Valhall Gpu Kernel Driver