216.73.216.36

CVE-2025-1246

· Published 02/06/2025 11:15 · Modified 02/06/2025 17:32

Labels: CVE-2025-1246 2025-06-02CVE-2025-1246CWE-119[email protected]

Essential information

Published
02/06/2025 11:15
Modified
02/06/2025 17:32
Author
Creator
CVSS
7.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r18p0 through r49p3, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r28p0 through r49p3, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p3, from r50p0 through r54p0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
arm / bifrost gpu userspace driver cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r18p0-r49p3:*:*:*:*:*:*:*
arm / bifrost gpu userspace driver cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r50p0-r51p0:*:*:*:*:*:*:*
arm / valhall gpu userspace driver cpe:2.3:a:arm:valhall_gpu_userspace_driver:r28p0-r49p3:*:*:*:*:*:*:*
arm / valhall gpu userspace driver cpe:2.3:a:arm:valhall_gpu_userspace_driver:r50p0-r54p0:*:*:*:*:*:*:*
arm / arm 5th gen gpu architecture userspace driver cpe:2.3:a:arm:arm_5th_gen_gpu_architecture_userspace_driver:r41p0-r49p3:*:*:*:*:*:*:*
arm / arm 5th gen gpu architecture userspace driver cpe:2.3:a:arm:arm_5th_gen_gpu_architecture_userspace_driver:r50p0-r54p0:*:*:*:*:*:*:*

References