PT-2021-4879 · Arm · Arm Mali Gpu Kernel Driver

Published

2021-03-18

·

Updated

2025-11-03

·

CVE-2021-28663

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Arm Mali GPU kernel driver versions Bifrost r0p0 through r28p0 before r29p0 Arm Mali GPU kernel driver versions Valhall r19p0 through r28p0 before r29p0 Arm Mali GPU kernel driver versions Midgard r4p0 through r30p0
Description The issue is related to the mishandling of GPU memory operations, leading to a use-after-free condition. This can result in privilege escalation or information disclosure. An attacker may exploit this issue to gain unauthorized access to protected information or elevate their privileges. The vulnerability can be exploited by a remote attacker.
Recommendations For Bifrost r0p0 through r28p0, update to version r29p0 or later to resolve the issue. For Valhall r19p0 through r28p0, update to version r29p0 or later to resolve the issue. For Midgard r4p0 through r30p0, update to a version later than r30p0 to resolve the issue. As a temporary workaround, consider restricting access to the GPU kernel driver to minimize the risk of exploitation.

Exploit

Fix

LPE

Use After Free

Weakness Enumeration

Related Identifiers

ASB-A-174259860
BDU:2021-05610
CVE-2021-28663

Affected Products

Arm Mali Gpu Kernel Driver