CVE-2025-1246
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
02/06/2025
Last modified:
02/07/2025
Description
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r18p0 through r49p3, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r28p0 through r49p3, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p3, from r50p0 through r54p0.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:*:*:*:*:*:*:*:* | r41p0 (including) | r49p4 (excluding) |
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:*:*:*:*:*:*:*:* | r50p0 (including) | r54p1 (excluding) |
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:*:*:*:*:*:*:*:* | r48p0 (including) | r49p4 (excluding) |
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r50p0:*:*:*:*:*:*:* | ||
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r51p0:*:*:*:*:*:*:* | ||
cpe:2.3:a:arm:valhall_gpu_userspace_driver:*:*:*:*:*:*:*:* | r28p0 (including) | r49p4 (excluding) |
cpe:2.3:a:arm:valhall_gpu_userspace_driver:*:*:*:*:*:*:*:* | r50p0 (including) | r54p1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page