« Volver al listado

CVE-2026-12285

Estado: Pendiente de análisisMedia (4)—

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory.

This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-12285",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-12285",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-10T17:56:41.282789Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "arm-security@arm.com",
      "affectedData": [
        {
          "vendor": "Arm Ltd",
          "product": "Bifrost GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "version": "r41p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p5"
            },
            {
              "status": "affected",
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r51p0"
            },
            {
              "status": "affected",
              "version": "r54p1",
              "versionType": "patch",
              "lessThanOrEqual": "r54p2"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Valhall GPU Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "version": "r41p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p5"
            },
            {
              "status": "affected",
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r54p3"
            },
            {
              "status": "affected",
              "version": "r55p0",
              "versionType": "patch"
            },
            {
              "status": "unaffected",
              "version": "r56p0",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Arm Ltd",
          "product": "Arm 5th Gen GPU Architecture Kernel Driver",
          "versions": [
            {
              "status": "affected",
              "version": "r41p0",
              "versionType": "patch",
              "lessThanOrEqual": "r49p5"
            },
            {
              "status": "affected",
              "version": "r50p0",
              "versionType": "patch",
              "lessThanOrEqual": "r54p3"
            },
            {
              "status": "affected",
              "version": "r55p0",
              "versionType": "patch"
            },
            {
              "status": "unaffected",
              "version": "r56p0",
              "versionType": "patch"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-08T15:18:40.170",
  "references": [
    {
      "url": "https://support.arm.com/documentation/111552/1-0/?lang=en",
      "source": "arm-security@arm.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "arm-security@arm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-416"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform valid GPU memory processing operations to access already freed memory.\n\n\n\nThis issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r51p0, from r54p1 through r54p2; Valhall GPU Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0."
    }
  ],
  "lastModified": "2026-09-10T18:17:54.777",
  "sourceIdentifier": "arm-security@arm.com"
}