7.8
CVE-2025-1246
- EPSS 0.03%
- Veröffentlicht 02.06.2025 11:15:21
- Zuletzt bearbeitet 02.07.2025 21:27:05
- Quelle arm-security@arm.com
- Teams Watchlist Login
- Unerledigt Login
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r18p0 through r49p3, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r28p0 through r49p3, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p3, from r50p0 through r54p0.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arm ≫ 5th Gen Gpu Architecture Userspace Driver Version >= r41p0 < r49p4
Arm ≫ 5th Gen Gpu Architecture Userspace Driver Version >= r50p0 < r54p1
Arm ≫ Bifrost Gpu Userspace Driver Version >= r48p0 < r49p4
Arm ≫ Bifrost Gpu Userspace Driver Versionr50p0
Arm ≫ Bifrost Gpu Userspace Driver Versionr51p0
Arm ≫ Valhall Gpu Userspace Driver Version >= r28p0 < r49p4
Arm ≫ Valhall Gpu Userspace Driver Version >= r50p0 < r54p1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.03% | 0.054 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.