CVE-2026-5729

Arm · Valhall GPU Kernel Driver and 5th Gen GPU Architecture Kernel Driver

A Use After Free vulnerability in Arm GPU kernel drivers allows a local non-privileged user to access freed memory during GPU processing operations.

Executive summary

A Use After Free vulnerability in Arm GPU kernel drivers could allow a local attacker to escalate privileges or cause system instability.

Vulnerability

This is a Use After Free (CWE-416) flaw within the GPU kernel drivers, which can be triggered by a local, non-privileged user process performing standard GPU operations. By accessing memory that has already been deallocated, an attacker may achieve unauthorized data access or execute arbitrary code.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high severity level that poses a significant risk to system integrity and confidentiality. Because successful exploitation allows for local privilege escalation, an attacker who has gained low-level access to a device could potentially take full control of the host system, leading to data theft or total service disruption.

Remediation

Immediate Action: Update the Arm Valhall GPU Kernel Driver and the Arm 5th Gen GPU Architecture Kernel Driver to release r56p0 or later.

Proactive Monitoring: Monitor system logs for unusual kernel crashes or GPU driver errors that may indicate exploitation attempts.

Compensating Controls: Restrict system access to untrusted users and ensure that only authorized applications can interact with GPU hardware interfaces.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of kernel-level drivers, organizations should prioritize updating their GPU driver stacks as soon as the vendor-provided patch is integrated into their respective operating system or firmware updates. Failure to remediate could allow local attackers to bypass security boundaries and compromise the underlying system.

More Arm CVEs

History

CVE Brief tracked this CVE 2 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.8 (3.1)
  4. Analyst report written

Sources