« Volver al listado

CVE-2025-0072

Estado: ModificadaAlta (7.8)—

Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.

This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p3, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p3, from r50p0 through r53p0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-416 (Use After Free) + AV:L/PR:L permite escalada local a código arbitrario. Acceso a memoria GPU liberada posibilita ejecución y lectura de datos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-0072",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-0072",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-12T15:50:43.159432Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "arm-security@arm.com",
      "affectedData": [
        {
          "vendor": "Arm Ltd",
          "product": "Valhall GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r49p4",
                  "status": "unaffected"
                }
              ],
              "version": "r29p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p3"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r54p0",
                  "status": "unaffected"
                }
              ],
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r53p0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Arm 5th Gen GPU Architecture Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r49p4",
                  "status": "unaffected"
                }
              ],
              "version": "r41p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p3"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r54p0",
                  "status": "unaffected"
                }
              ],
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r53p0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-02T10:15:15.947",
  "references": [
    {
      "url": "https://developer.arm.com/documentation/110465/latest/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "arm-security@arm.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "arm-security@arm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to already freed memory.\n\nThis issue affects Valhall GPU Kernel Driver: from r29p0 through r49p3, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p3, from r50p0 through r53p0."
    },
    {
      "lang": "es",
      "value": "La vulnerabilidad \"Use After Free\" en el controlador del kernel de GPU Valhall de Arm Ltd. El controlador del kernel de la arquitectura de GPU Arm de 5.ª generación de Arm Ltd permite que un proceso de usuario local sin privilegios realice operaciones incorrectas de procesamiento de memoria de GPU para acceder a la memoria ya liberada. Este problema afecta al controlador del kernel de GPU Valhall: de r29p0 a r49p3 y de r50p0 a r53p0; y al controlador del kernel de la arquitectura de GPU Arm de 5.ª generación: de r41p0 a r49p3 y de r50p0 a r53p0."
    }
  ],
  "lastModified": "2026-06-17T08:25:45.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:arm:5th_gen_gpu_architecture_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8ACF6697-A7EB-4131-937C-AC3A1FB49923",
              "versionEndIncluding": "r49p3",
              "versionStartIncluding": "r41p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:5th_gen_gpu_architecture_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20FA69E1-1B9E-423E-859D-D47526D843DD",
              "versionEndIncluding": "r53p0",
              "versionStartIncluding": "r50p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28768B33-00EF-4196-8E9F-7A2D7C33C01C",
              "versionEndIncluding": "r49p3",
              "versionStartIncluding": "r29p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CF9F3C4-CF1F-4A2B-B6C9-2CA9F8658B84",
              "versionEndIncluding": "r53p0",
              "versionStartIncluding": "r50p0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "arm-security@arm.com"
}