HIGH
CVE-2021-28663
CVSS
8.8
KEV
Description
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
Summary dbcve.org
A use-after-free vulnerability in the Arm Mali GPU kernel driver allows local privilege escalation or information disclosure due to mishandled GPU memory operations. The flaw exists in Bifrost (r0p0-r28p0), Valhall (r19p0-r28p0), and Midgard (r4p0-r30p0) GPU architectures.
Mitigation
Update the Mali GPU driver to r29p0 or later to address the use-after-free vulnerability in GPU memory operations.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
12.08%
Probability of exploitation in next 30 days
96th percentile
References
https://developer.arm.com/support/arm-security-updates
Vendor Advisory
https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver
Vendor Advisory
https://github.com/lntrx/CVE-2021-28663
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28663
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.