CVE-2026-0860
massLocal Kernel Information Disclosure in Arm Valhall and 5th Gen GPU Drivers
CVE-2026-0860 is an exposure-of-sensitive-information vulnerability (CWE-200, rated High at CVSS 3.1 7.5) in Arm's Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver, the Mali-family GPU kernel driver components shipped in Android smartphones, tablets, and other embedded or automotive Linux systems. A local, non-privileged user process can trigger improper GPU memory processing operations that expose sensitive kernel information to that process. An attacker gains read access to sensitive kernel memory only (the CVSS vector shows no integrity or availability impact), which can assist further attacks such as privilege-escalation steps. Affected deployments are those running Valhall driver releases r29p0 through r49p5, r50p0 through r54p3, or r55p0, or 5th Gen GPU Architecture driver releases r41p0 through r49p5, r50p0 through r54p3, or r55p0. There is currently no known exploitation: no public proof of concept exists, the issue is not listed in CISA KEV, and EPSS estimates roughly a 0.1% probability of exploitation within the next 30 days.
What to do: Update affected systems to an Arm GPU kernel driver release newer than r55p0, delivered through your SoC or device vendor's (OEM) security updates, since these drivers typically reach end devices via vendor Android/Linux updates. Inventory Android and embedded Linux fleets by checking the GPU kernel driver version against the affected ranges. Because this is a local information-disclosure issue with no known exploitation, prioritize devices that run untrusted third-party apps, and note the published CVSS vector uses AV:N while the description describes local access.
| Arm Ltd Valhall GPU Kernel Driver | r29p0 through r49p5, r50p0 through r54p3, r55p0 |
| Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver | r41p0 through r49p5, r50p0 through r54p3, r55p0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to sensitive kernel information. This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.