Vulnerability Details CVE-2025-1246
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to perform valid GPU processing operations, including via WebGL or WebGPU, to access outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r18p0 through r49p3, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r28p0 through r49p3, from r50p0 through r54p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p3, from r50p0 through r54p0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.4%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2025-1246
-
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:r41p0
-
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:r49p3
-
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:r50p0
-
cpe:2.3:a:arm:5th_gen_gpu_architecture_userspace_driver:r54p0
-
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r48p0
-
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r49p3
-
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r50p0
-
cpe:2.3:a:arm:bifrost_gpu_userspace_driver:r51p0
-
cpe:2.3:a:arm:valhall_gpu_userspace_driver:r28p0
-
cpe:2.3:a:arm:valhall_gpu_userspace_driver:r49p3
-
cpe:2.3:a:arm:valhall_gpu_userspace_driver:r50p0
-
cpe:2.3:a:arm:valhall_gpu_userspace_driver:r54p0