CVE-2025-0072 is a Use After Free vulnerability affecting Arm Valhall and 5th Gen GPU Architecture Kernel Drivers (versions r29p0-r53p0 and r41p0-r53p0 respectively). A local, non-privileged user can exploit this flaw to improperly process GPU memory, gaining access to previously freed memory. This vulnerability is rated HIGH severity (CVSS 7.8), indicating a significant risk. An attacker with local access can achieve high confidentiality, integrity, and availability impacts with low attack complexity, requiring no user interaction. While not currently listed in CISA's KEV catalog or having public exploit code in Metasploit, Nuclei, or ExploitDB, there is community discussion and media coverage, including an article detailing its potential use to bypass Memory Tagging Extension (MTE).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r41p0, <= r49p3CPE matchmatch criteria | cpe:2.3:a:arm:5th_gen_gpu_architecture_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r50p0, <= r53p0CPE matchmatch criteria | cpe:2.3:a:arm:5th_gen_gpu_architecture_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r29p0, <= r49p3CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r50p0, <= r53p0CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.