Skip to content
COOEY

EXPOSURES › CVE-2024-4610

CVE-2024-4610

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-06-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4610 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatchedransomware

Arm's Mali GPU kernel driver contains a high-severity use-after-free vulnerability actively exploited in the wild.

A local user can exploit this use-after-free flaw in Arm's Bifrost and Valhall GPU drivers to access freed memory, posing a significant risk to DIB systems relying on Arm hardware. Because the vulnerability is actively exploited and linked to ransomware campaigns, vendors must ensure patches are deployed immediately to prevent unauthorized access to sensitive data.

Shame score — The vulnerability is actively exploited in the wild and linked to ransomware, indicating a failure to patch or secure the supply chain promptly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.