ZeroHour

CVE-2026-7476

mass

Use-After-Free in Arm Bifrost, Valhall and 5th Gen Mali GPU Kernel Drivers

CVSS 3.1
7.8 high
EPSS
<1%p4
Published
()
Modified
AI analysis

CVE-2026-7476 is a use-after-free (CWE-416) in Arm's Bifrost, Valhall and Arm 5th Gen GPU Architecture (Mali) kernel drivers that allows a local, non-privileged user process to perform improper GPU memory processing operations and access memory that has already been freed. It is triggered by a local user process performing GPU memory operations against an affected driver revision; the attack vector is purely local and requires no user interaction. The CVSS 3.1 score of 7.8 (High) reflects high impact on confidentiality, integrity and availability, meaning the flaw can potentially let an unprivileged process read or corrupt memory it should not be able to reach. Anyone running a device whose kernel integrates one of the affected Bifrost, Valhall or 5th Gen Mali driver revisions — typically Arm-based smartphones, tablets and embedded systems built around Mali GPUs — is affected. There is no known public proof of concept, it is not in CISA KEV, and EPSS places the 30-day exploitation probability at roughly 0.1% (4th percentile).

What to do: Inventory which Mali GPU kernel driver revision your fleet's kernels ship with (revisions follow the r<xx>p<n> naming used in the advisory) and upgrade to a release outside the affected ranges as published by Arm; on end devices, apply OS/kernel updates from your device or SoC vendor as they land. Because any local unprivileged process can trigger the flaw, prioritize patching shared and multi-user systems first. No public exploit is known and it is not in CISA KEV, so there is currently no evidence of active exploitation.

Affected
Arm Ltd Bifrost GPU Kernel Driverr49p3 through r49p5, r51p0, r54p1 through r54p2
Arm Ltd Valhall GPU Kernel Driverr49p3 through r49p5, r51p0 through r54p3, r55p0
Arm Ltd Arm 5th Gen GPU Architecture Kernel Driverr49p3 through r49p5, r51p0 through r54p3, r55p0
Estimated exposure
massplausibly on the order of 100M+ devices (affected Mali driver branches ship inside SoC/vendor OS kernels across a large share of Arm-based smartphones, tablets… — This is a deployment-pattern estimate, not a scanned count: Bifrost, Valhall and 5th Gen Mali GPUs are licensed into a large fraction of Arm-based mobile and embedded SoCs and these driver revision branches shipped in vendor OS builds, but…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to access already freed memory. This issue affects Bifrost GPU Kernel Driver: from r49p3 through r49p5, r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r49p3 through r49p5, from r51p0 through r54p3, r55p0.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.