« Volver al listado

CVE-2025-0427

Estado: ModificadaAlta (7.8)—

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r8p0 through r49p3, from r50p0 through r51p0; Valhall GPU Kernel Driver: from r19p0 through r49p3, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p3, from r50p0 through r53p0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) sin interacción (UI:N) en driver GPU: escalada de privilegios. Use-after-free permite acceso a memoria liberada para ejecutar código o leer datos en kernel.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-0427",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-0427",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-12T15:51:55.333310Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "arm-security@arm.com",
      "affectedData": [
        {
          "vendor": "Arm Ltd",
          "product": "Bifrost GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r49p4",
                  "status": "unaffected"
                }
              ],
              "version": "r8p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p3"
            },
            {
              "status": "affected",
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r51p0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Valhall GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r49p4",
                  "status": "unaffected"
                }
              ],
              "version": "r19p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p3"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r54p0",
                  "status": "unaffected"
                }
              ],
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r53p0"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Arm 5th Gen GPU Architecture Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r49p4",
                  "status": "unaffected"
                }
              ],
              "version": "r41p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p3"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "r54p0",
                  "status": "unaffected"
                }
              ],
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r53p0"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-05-02T10:15:16.637",
  "references": [
    {
      "url": "https://developer.arm.com/documentation/110465/latest/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "arm-security@arm.com"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "arm-security@arm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r8p0 through r49p3, from r50p0 through r51p0; Valhall GPU Kernel Driver: from r19p0 through r49p3, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p3, from r50p0 through r53p0."
    },
    {
      "lang": "es",
      "value": "La vulnerabilidad \"Use After Free\" en los controladores del kernel de GPU Bifrost de Arm Ltd, Valhall de Arm Ltd y Arm 5th Gen GPU Architecture Kernel Driver de Arm Ltd permite que un proceso de usuario local sin privilegios realice operaciones de procesamiento de GPU válidas para obtener acceso a memoria ya liberada. Este problema afecta a los controladores del kernel de GPU Bifrost: de r8p0 a r49p3 y de r50p0 a r51p0; Valhall de Arm Ltd: de r19p0 a r49p3 y de r50p0 a r53p0; Arm 5th Gen GPU Architecture Kernel Driver de Arm Ltd: de r41p0 a r49p3 y de r50p0 a r53p0."
    }
  ],
  "lastModified": "2026-06-17T08:26:27.290",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:arm:5th_gen_gpu_architecture_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8ACF6697-A7EB-4131-937C-AC3A1FB49923",
              "versionEndIncluding": "r49p3",
              "versionStartIncluding": "r41p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:5th_gen_gpu_architecture_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20FA69E1-1B9E-423E-859D-D47526D843DD",
              "versionEndIncluding": "r53p0",
              "versionStartIncluding": "r50p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36C94DD7-49EE-46ED-9ECB-09CE22FAD3FB",
              "versionEndIncluding": "r49p3",
              "versionStartIncluding": "r8p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3439BB1-431A-4480-ADA5-23F4A680659F",
              "versionEndIncluding": "r51p0",
              "versionStartIncluding": "r50p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75B9241A-E748-4CAD-B08D-311A9C6BC9A5",
              "versionEndIncluding": "r49p3",
              "versionStartIncluding": "r19p0"
            },
            {
              "criteria": "cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5CF9F3C4-CF1F-4A2B-B6C9-2CA9F8658B84",
              "versionEndIncluding": "r53p0",
              "versionStartIncluding": "r50p0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "arm-security@arm.com"
}