← Vulnerability feed

Vulnerability record · CVE-2024-4610 · published 7 June 2024

CVE-2024-4610: Arm Mali GPU kernel driver use-after-free lets local user access freed memory

Arm · Bifrost Gpu Kernel Driver

The Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU memory operations. The flaw spans driver releases r34p0 through r40p0. Because it is a kernel memory-safety bug, successful abuse can corrupt or read freed GPU memory, which is a serious local privilege-escalation primitive.

7.8 CVSS 3.1 High CISA KEV since 12 Jun 2024 EPSS 0.76% · top 46.6% CWE-416 · Use after free
7.8CVSS 3.1 base score
0.76%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r34p0 through r40p0; Valhall GPU Kernel Driver: from r34p0 through r40p0.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is a kernel use-after-free with high confidentiality, integrity and availability impact and confirmed exploitation per CISA KEV, though it requires local access.

What it is

The Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU memory operations. The flaw spans driver releases r34p0 through r40p0. Because it is a kernel memory-safety bug, successful abuse can corrupt or read freed GPU memory, which is a serious local privilege-escalation primitive.

Impact

An attacker gains access to already freed GPU memory, enabling memory disclosure and corruption that can lead to privilege escalation or code execution in kernel context. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so any local non-privileged process able to issue GPU memory operations can reach the flaw. No network or remote path is described.

Exploitation

CVE-2024-4610 was added to CISA KEV on 2024-06-12 with a 2024-07-03 remediation due date, indicating known exploitation in the wild. EPSS is low (0.00758, ~53rd percentile), and no ransomware campaign use is documented.

What to do

  • Apply the Arm Mali GPU driver update that resolves the use-after-free for Bifrost and Valhall releases r34p0 through r40p0, per the Arm Security Center advisory.
  • If a patched driver is not available for the device, discontinue use of the affected product as directed by CISA KEV required action.
  • Restrict local access to affected devices and limit untrusted code execution, since exploitation requires only a local non-privileged user.
  • Track the CISA KEV due date (2024-07-03) and confirm remediation status across all devices using the affected drivers.

Detection

  • Monitor for crashes or anomalous behavior in GPU driver processes that may indicate use-after-free access.
  • Audit which devices run Bifrost or Valhall GPU kernel drivers in the r34p0 to r40p0 range and verify patch state.
  • Watch for local privilege-escalation activity originating from non-privileged processes interacting with GPU memory operations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-4610 to the Known Exploited Vulnerabilities catalog on 12 June 2024 as "Arm Mali GPU Kernel Driver Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 July 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-4610 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38181Arm Mali GPU kernel driver use-after-free via mishandled GPU memory operationsThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affe…KEVEPSS 14%analysed8.8CVE-2021-29256Arm Mali GPU kernel driver use-after-free allows privilege escalationThe Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitat…KEVEPSS 3.0%analysed8.8CVE-2021-28663Arm Mali GPU kernel driver use-after-free privilege escalationThe Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker…KEVEPSS 12%analysed8.8CVE-2021-28664Arm Mali GPU kernel driver out-of-bounds write allows privilege escalationThe Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privi…KEVEPSS 5.4%analysed7.8CVE-2022-22706Arm Mali GPU Kernel Driver read-only memory write flawThe Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting M…KEVEPSS 1.1%analysed5.5CVE-2023-4211Arm Mali GPU Kernel Driver use-after-free via improper GPU memory handlingThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A l…KEVEPSS 1.1%analysed3.3CVE-2023-26083Arm Mali GPU Kernel Driver memory leak exposes kernel metadataThe Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0…KEVEPSS 1.2%analysed9.8CVE-2022-28349Arm bifrost gpu kernel driver use after free vulnerabilityArm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2024-4610), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.