CVE-2024-0153
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
01/07/2024
Last modified:
27/03/2025
Description
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture Firmware allows a local non-privileged user to make improper GPU processing operations to access a limited amount outside of buffer bounds. If the operations are carefully prepared, then this in turn could give them access to all system memory. This issue affects Valhall GPU Firmware: from r29p0 through r46p0; Arm 5th Gen GPU Architecture Firmware: from r41p0 through r46p0.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:arm:5th_gen_gpu_architecture_firmware:*:*:*:*:*:*:*:* | r41p0 (including) | r47p0 (excluding) |
| cpe:2.3:o:arm:valhall_gpu_firmware:*:*:*:*:*:*:*:* | r29p0 (including) | r47p0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



