Vulnerability Intelligence Report
Mali GPU Userspace Driver allows an Out-of-Bounds access
CVE-2025-0050
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to make valid GPU processing operations, including via WebGL or WebGPU, to access a limited amount outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r0p0 through r49p2, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r19p0 through r49p2, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p2, from r50p0 through r53p0.
No Active Exploit Signals
CVSS Base Score
5.9
MEDIUM
Exploitability:2.6
Impact Score:3.4
EPSS Probability:0.14%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-119 ↗CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Arm Ltd | Valhall GPU Userspace Driver | r19p0 <= r49p2 (affected), r50p0 <= r53p0 (affected) |
| Arm Ltd | Arm 5th Gen GPU Architecture Userspace Driver | r41p0 <= r49p2 (affected), r50p0 <= r53p0 (affected) |
| Arm Ltd | Bifrost GPU Userspace Driver | r0p0 <= r49p2 (affected), r50p0 <= r51p0 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.139%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Arm Limited · Open Source · UK |
| Reserved | 2024-12-04T12:04:28 |
| Published | 2025-04-07T12:02:02 |
| Patch Date | 2025-04-07 |
| Last Updated | 2025-04-10T14:06:48 |
Community Chatter & Buzz