CVE-2021-28663
HIGH(8.8)KEVElevated Risk
Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
Description
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| arm | bifrost gpu kernel driver | >= r0p0, < r29p0 |
| arm | midgard gpu kernel driver | >= r4p0, < r31p0 |
| arm | valhall gpu kernel driver | >= r19p0, < r29p0 |
Multiple CVSS Assessments
Source: [email protected](Primary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- https://developer.arm.com/support/arm-security-updates(Vendor Advisory)
- https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver(Vendor Advisory)
- https://github.com/lntrx/CVE-2021-28663(Exploit)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28663(US Government Resource)
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.