CVE-2025-1246

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
02/06/2025
Last modified:
02/07/2025

Description

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r18p0 through r49p3, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r28p0 through r49p3, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p3, from r50p0 through r54p0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:*:*:*:*:*:*:*:* r41p0 (including) r49p4 (excluding)
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:*:*:*:*:*:*:*:* r50p0 (including) r54p1 (excluding)
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:*:*:*:*:*:*:*:* r48p0 (including) r49p4 (excluding)
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r50p0:*:*:*:*:*:*:*
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r51p0:*:*:*:*:*:*:*
cpe:2.3:a:arm:valhall_gpu_userspace_driver:*:*:*:*:*:*:*:* r28p0 (including) r49p4 (excluding)
cpe:2.3:a:arm:valhall_gpu_userspace_driver:*:*:*:*:*:*:*:* r50p0 (including) r54p1 (excluding)


References to Advisories, Solutions, and Tools