⚠ Actively exploited
Added to CISA KEV on 2024-06-12. Federal agencies required to patch by 2024-07-03. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2024-4610Use After Free in ARM Bifrost GPU Kernel Driver

Severity
7.8HIGHNVD
EPSS
0.8%
top 26.61%
CISA KEV
KEV
Added 2024-06-12
Due 2024-07-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 7
KEV addedJun 12
KEV dueJul 3
Latest updateDec 3
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver: from r34p0 through r40p0.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDarm/bifrost_gpu_kernel_driverr34p0r41p0
NVDarm/valhall_gpu_kernel_driverr34p0r41p0
CVEListV5arm_ltd/bifrost_gpu_kernel_driverr34p0r40p0
CVEListV5arm_ltd/valhall_gpu_kernel_driverr34p0r40p0
Debianlinux/linux_kernel< 6.1.85-1+1

🔴Vulnerability Details

3
GHSA
GHSA-p5rh-rvqf-4976: Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improp2024-06-07
OSV
CVE-2024-26929: In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of fcport The server was crashing after LOGO beca2024-05-01
VulnCheck
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability2024

📋Vendor Advisories

4
Red Hat
kernel: x86/bugs: Use code segment selector for VERW operand2024-10-29
Android
CVE-2024-4610: Mali2024-07-01
CISA
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability2024-06-12
Red Hat
hw:arm: Mali GPU Kernel Driver allows improper GPU memory processing operations2024-06-07

🕵️Threat Intelligence

2
Mandiant
Intellexa’s Prolific Zero-Day Exploits Continue2025-12-03
Mandiant
Sanctioned but Still Spying: Intellexa’s Prolific Zero-Day Exploits Continue2025-12-03

💬Community

1
Bugzilla
CVE-2024-4610 hw:arm: Mali GPU Kernel Driver allows improper GPU memory processing operations2024-06-13