CVE-2024-1065 is a use-after-free vulnerability in Arm Ltd GPU kernel drivers affecting the Bifrost, Valhall, and Arm 5th Gen GPU Architecture driver lines. According to the provided description, a local non-privileged user can trigger improper GPU memory processing operations that result in access to memory that has already been freed. The affected versions are r45p0 through r48p0 for all three driver families. Because the flaw is in a kernel driver, exploitation occurs in a privileged kernel-space component even though the attacker starts from an unprivileged local context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a README and a single C exploit PoC. The exploit is a local Linux privilege-escalation proof of concept for CVE-2024-1065, abusing a physical page use-after-free in the ARM Mali GPU kernel driver. Structure is simple: README explains the technique and build/use steps; exploit.c implements the full chain. The code pins execution to the current CPU, opens the target shared library (/lib/x86_64-linux-gnu/libpam.so.0) many times to prepare page-cache spraying, then initializes the Mali driver through /dev/mali0 using version-check and setup ioctls. It allocates an anonymous page, imports it into the driver with KBASE_IOCTL_MEM_IMPORT, maps the imported page twice, and frees the original mappings in a way that leaves a stale userspace alias to a freed physical page. It then repeatedly evicts and rereads a chosen page of the target library using posix_fadvise(..., POSIX_FADV_DONTNEED) and pread() so the kernel reuses MIGRATE_MOVABLE pages until the freed page is recycled as page cache for the library. Overlap is confirmed by probing a byte at the chosen function offset through the stale mapping. Once overlap is achieved, the exploit writes hardcoded x86-64 shellcode into the aliased page-cache page. The shellcode calls setuid(0), setgid(0), and execve("/bin/sh"). Finally, the exploit execves /usr/bin/passwd, relying on the SUID-root binary to load the now-corrupted libpam.so.0 page from memory and execute the injected code as root. No network activity exists; all observables are local file/device paths and ioctl interactions. This is a real exploit PoC with a functional payload, but it is narrowly targeted and hardcoded rather than framework-driven.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.