CVE-2026-7476
Arm · Bifrost, Valhall, and 5th Gen GPU Kernel Drivers
A Use After Free vulnerability in Arm GPU kernel drivers allows a local, non-privileged user to perform improper memory operations, potentially resulting in unauthorized memory access.
Executive summary
A high-severity Use After Free vulnerability in multiple Arm GPU kernel drivers could allow local attackers to gain unauthorized access to system memory.
Vulnerability
The flaw is a Use After Free vulnerability (CWE-416) within the GPU kernel drivers. It allows a local, non-privileged user process to trigger improper memory management operations, enabling the process to access memory that has already been freed.
Business impact
Successful exploitation of this vulnerability allows a local attacker to achieve high-level impacts, including potential privilege escalation or data corruption, as indicated by the CVSS score of 7.8. While the attack requires local access, the ability to interact directly with kernel-level memory poses a significant risk to the integrity and confidentiality of the host operating system.
Remediation
Immediate Action: System administrators should update Valhall and 5th Gen GPU Kernel Drivers to version r56p0 or later. For Bifrost GPU drivers, monitor the Arm support documentation for the release of a corresponding patch.
Proactive Monitoring: Review system logs for unusual kernel-level activity or crashes related to the GPU driver, which may indicate attempts to exploit memory management flaws.
Compensating Controls: Limit access to the affected system to trusted, authorized users only to mitigate the risk of local exploitation by non-privileged accounts.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the high CVSS severity and the potential for kernel-level memory corruption, administrators must prioritize patching as soon as vendor updates become available. Organizations should track the status of Bifrost driver updates via the official Arm support documentation and apply all security updates immediately upon release to prevent local privilege escalation.
More Arm CVEs
History
CVE Brief tracked this CVE 2 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.8 (3.1)
- Analyst report written