Wednesday, April 16, 2025
Homecyber securityArm Released a Security Update Mali GPU Kernel Driver Vulnerabilities

Arm Released a Security Update Mali GPU Kernel Driver Vulnerabilities

Published on

SIEM as a Service

Follow Us on Google News

On February 3, 2025, Arm disclosed a vulnerability in the Mali GPU Kernel Driver that allows improper GPU processing operations.

This issue affects Valhall GPU Kernel Driver versions ranging from r48p0 to r49p1 and r50p0 to r52p0, as well as the Arm 5th Gen GPU Architecture Kernel Driver within the same version ranges.

The flaw enables a local, non-privileged user to access already freed memory through improper GPU operations.

- Advertisement - Google News

Arm has resolved this issue in Valhall and Arm 5th Gen GPU Architecture Kernel Driver versions r49p2 and r53p0.

Users are advised to upgrade to these versions to mitigate potential risks.

System Unresponsiveness via Valid GPU Memory Processing (CVE-2024-6790)

Another critical vulnerability reported on February 3, 2025, involves the Mali GPU Kernel Driver causing system unresponsiveness.

This issue impacts Bifrost, Valhall, and Arm 5th Gen GPU Architecture Kernel Drivers across various versions, including r44p1, r46p0 to r49p0, and r50p0 to r51p0.

CVE ID(s)DescriptionFixed in Versions
CVE-2025-0015Allows improper GPU processing operationsr49p2, r53p0
CVE-2024-6790Can cause system unresponsiveness via GPU memory opsr49p1, r52p0
CVE-2024-3655, CVE-2024-2937, CVE-2024-4607Improper GPU memory processing operationsr49p1, r50p0
CVE-2024-0153Affects GPU firmware, potentially enabling full system memory accessr47p0

Exploitation of this vulnerability allows a non-privileged user to execute valid GPU memory processing operations such as those via WebGL or WebGPU that render the entire system unresponsive.

Fixes have been implemented in Bifrost GPU Kernel Driver version r49p1 and Valhall/Arm 5th Gen GPU Architecture Kernel Driver versions r49p1 and r52p0.

Users are urged to update their systems accordingly. These vulnerabilities highlight the importance of timely updates to protect against potential exploitation and maintain system integrity.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN Sandox -> Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Landmark Admin Suffers Major Breach, Exposing Data of 1.6M+ Users

Landmark Admin, LLC (“Landmark”), a Texas-based third-party administrator for life insurance carriers, has confirmed...

SquareX to Reveal Critical Data Splicing Attack at BSides SF, Exposing Major DLP Vulnerability

SquareX researchers Jeswin Mathai and Audrey Adeline will be disclosing a new class of data exfiltration techniques at BSides...

Firefox Fixes High-Severity Vulnerability Causing Memory Corruption via Race Condition

Mozilla has released Firefox 137.0.2, addressing a high-severity security flaw that could potentially allow...

Tails 6.14.2 Released with Critical Fixes for Linux Kernel Vulnerabilities

The Tails Project has urgently released Tails 6.14.2, addressing critical security vulnerabilities in the Linux...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Landmark Admin Suffers Major Breach, Exposing Data of 1.6M+ Users

Landmark Admin, LLC (“Landmark”), a Texas-based third-party administrator for life insurance carriers, has confirmed...

SquareX to Reveal Critical Data Splicing Attack at BSides SF, Exposing Major DLP Vulnerability

SquareX researchers Jeswin Mathai and Audrey Adeline will be disclosing a new class of data exfiltration techniques at BSides...

Firefox Fixes High-Severity Vulnerability Causing Memory Corruption via Race Condition

Mozilla has released Firefox 137.0.2, addressing a high-severity security flaw that could potentially allow...