Buffer overflow in ARM products - CVE-2025-0050
Published: April 7, 2025
Vulnerability identifier: #VU107131
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0050
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
Affected software
Bifrost GPU Userspace Driver
Valhall GPU Userspace Driver
Arm 5th Gen GPU Architecture Userspace Driver
Google Android
Valhall GPU Userspace Driver
Arm 5th Gen GPU Architecture Userspace Driver
Google Android
How to mitigate CVE-2025-0050
Install updates from vendor's website.
Bifrost GPU Userspace Driver - update to r49p3
Valhall GPU Userspace Driver - addressed in versions r49p3, r54p0
Arm 5th Gen GPU Architecture Userspace Driver - addressed in versions r49p3, r54p0
Google Android - addressed in versions 13 2025-04-05, 14 2025-04-05, 15 2025-04-05
Valhall GPU Userspace Driver - addressed in versions r49p3, r54p0
Arm 5th Gen GPU Architecture Userspace Driver - addressed in versions r49p3, r54p0
Google Android - addressed in versions 13 2025-04-05, 14 2025-04-05, 15 2025-04-05