EXPOSURES › CVE-2024-4610
CVE-2024-4610
HIGH ⌖ ON CISA KEV · EXPLOITEDArm's Mali GPU kernel driver contains a high-severity use-after-free vulnerability actively exploited in the wild.
A local user can exploit this use-after-free flaw in Arm's Bifrost and Valhall GPU drivers to access freed memory, posing a significant risk to DIB systems relying on Arm hardware. Because the vulnerability is actively exploited and linked to ransomware campaigns, vendors must ensure patches are deployed immediately to prevent unauthorized access to sensitive data.
Shame score — The vulnerability is actively exploited in the wild and linked to ransomware, indicating a failure to patch or secure the supply chain promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.