// For flags

CVE-2024-4610

Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

Act
*SSVC
Descriptions

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver: from r34p0 through r40p0.

Vulnerabilidad de Use After Free en Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver permite a un usuario local sin privilegios realizar operaciones de procesamiento de memoria GPU incorrectas para obtener acceso a la memoria ya liberada. Este problema afecta al controlador Bifrost GPU Kernel: de r34p0 a través de r40p0; Controlador del kernel de GPU Valhall: desde r34p0 hasta r40p0.

Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Act
Exploitation
Active
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-05-07 CVE Reserved
  • 2024-06-07 CVE Published
  • 2024-06-12 Exploited in Wild
  • 2024-07-03 KEV Due Date
  • 2024-08-01 CVE Updated
  • 2024-08-15 EPSS Updated
  • ---------- First Exploit
CWE
  • CWE-416: Use After Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arm
Search vendor "Arm"
Bifrost Gpu Kernel Driver
Search vendor "Arm" for product "Bifrost Gpu Kernel Driver"
>= r34p0 < r41p0
Search vendor "Arm" for product "Bifrost Gpu Kernel Driver" and version " >= r34p0 < r41p0"
-
Affected
Arm
Search vendor "Arm"
Valhall Gpu Kernel Driver
Search vendor "Arm" for product "Valhall Gpu Kernel Driver"
>= r34p0 < r41p0
Search vendor "Arm" for product "Valhall Gpu Kernel Driver" and version " >= r34p0 < r41p0"
-
Affected