Buffer overflow in ARM products - CVE-2025-0050

 

Buffer overflow in ARM products - CVE-2025-0050

Published: April 7, 2025


Vulnerability identifier: #VU107131
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0050
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.


Affected software

Bifrost GPU Userspace Driver
Valhall GPU Userspace Driver
Arm 5th Gen GPU Architecture Userspace Driver
Google Android

How to mitigate CVE-2025-0050

Install updates from vendor's website.

Bifrost GPU Userspace Driver - update to r49p3
Valhall GPU Userspace Driver - addressed in versions r49p3, r54p0
Arm 5th Gen GPU Architecture Userspace Driver - addressed in versions r49p3, r54p0
Google Android - addressed in versions 13 2025-04-05, 14 2025-04-05, 15 2025-04-05

External References

Related Security Bulletins