7.7
CVE-2026-9040
- EPSS 0.11%
- Veröffentlicht 08.09.2026 14:21:22
- Zuletzt bearbeitet 10.09.2026 18:18:16
- Erkennungen
Mali GPU Kernel Driver allows denial of service or disclosure of sensitive information
A race condition vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to cause a denial of service or disclose sensitive information. This issue affects Bifrost GPU Kernel Driver: from r12p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r19p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerArm Ltd
≫
Produkt
Bifrost GPU Kernel Driver
Default Statusunaffected
Version <=
r49p5
Version
r12p0
Status
affected
Version <=
r51p0
Version
r50p0
Status
affected
Version <=
r54p2
Version
r54p1
Status
affected
HerstellerArm Ltd
≫
Produkt
Valhall GPU Kernel Driver
Default Statusunaffected
Version <=
r49p5
Version
r19p0
Status
affected
Version <=
r54p3
Version
r50p0
Status
affected
Version
r55p0
Status
affected
Version
r56p0
Status
unaffected
HerstellerArm Ltd
≫
Produkt
Arm 5th Gen GPU Architecture Kernel Driver
Default Statusunaffected
Version <=
r49p5
Version
r41p0
Status
affected
Version <=
r54p3
Version
r50p0
Status
affected
Version
r55p0
Status
affected
Version
r56p0
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.015 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.7 | 2.5 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
|
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
https://support.arm.com/documentation/111552/1-0/?lang=en