CVE-2026-0860
Awaiting Analysis Awaiting Analysis - Queue

Information Disclosure in Arm Valhall GPU Kernel Driver

Vulnerability report for CVE-2026-0860, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: Arm Limited

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to perform improper GPU memory processing operations to gain access to sensitive kernel information. This issue affects Valhall GPU Kernel Driver: from r29p0 through r49p5, from r50p0 through r54p3, r55p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p5, from r50p0 through r54p3, r55p0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
arm_ltd valhall_gpu_kernel_driver From r29p0 (inc) to r49p5 (inc)
arm_ltd valhall_gpu_kernel_driver From r50p0 (inc) to r54p3 (inc)
arm_ltd valhall_gpu_kernel_driver to r55p0 (inc)
arm_ltd arm_5th_gen_gpu_architecture_kernel_driver From r41p0 (inc) to r49p5 (inc)
arm_ltd arm_5th_gen_gpu_architecture_kernel_driver From r50p0 (inc) to r54p3 (inc)
arm_ltd arm_5th_gen_gpu_architecture_kernel_driver to r55p0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a local non-privileged user process to improperly process GPU memory, potentially gaining access to sensitive kernel information. It affects specific versions of Arm Ltd's Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver.

Impact Analysis

A local attacker could exploit this to read sensitive kernel memory, potentially exposing confidential data or system credentials. This could lead to further system compromise or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected drivers may face compliance violations and potential fines.

Mitigation Strategies

Update the Valhall GPU Kernel Driver and Arm 5th Gen GPU Architecture Kernel Driver to versions beyond the affected ranges (r49p5, r54p3, r55p0). Remove local non-privileged user access to GPU memory processing operations until patches are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-0860. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart