CVE-2026-0860
Arm · Valhall GPU Kernel Driver, Arm 5th Gen GPU Architecture Kernel Driver
A local information disclosure vulnerability in Arm GPU kernel drivers allows non-privileged users to access sensitive kernel memory via improper GPU memory processing operations.
Executive summary
A high-severity information disclosure vulnerability in Arm Valhall and 5th Gen GPU kernel drivers allows local attackers to access sensitive kernel memory.
Vulnerability
This is an exposure of sensitive information (CWE-200) caused by improper memory processing in the GPU kernel driver, which can be triggered by a local, non-privileged user process to read restricted kernel memory.
Business impact
Successful exploitation allows a local attacker to bypass memory isolation boundaries, potentially leading to the compromise of sensitive kernel-level information. While the CVSS score of 7.5 indicates a high technical risk, the requirement for local access necessitates a focus on multi-user environments or systems where untrusted code execution is possible. The disclosure of kernel data can facilitate further privilege escalation or bypass security protections, posing a significant risk to system integrity and confidentiality.
Remediation
Immediate Action: Update the affected Arm GPU kernel drivers to version r56p0 or later, as specified in the vendor documentation.
Proactive Monitoring: Monitor system logs for unusual kernel-mode activities or unauthorized memory access attempts originating from non-privileged user processes.
Compensating Controls: Implement strict user privilege controls to limit the ability of non-authorized users to execute arbitrary code or interact directly with hardware drivers on sensitive systems.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for unauthorized access to sensitive kernel information, it is imperative that organizations utilizing Arm hardware prioritize the deployment of the r56p0 driver update. Administrators should verify the driver versions currently in use across their infrastructure and schedule maintenance windows to apply the necessary patches immediately to eliminate this exposure.
More Arm CVEs
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written