PT-2021-5045 · Arm · Arm Mali Graphics Processing Unit

Published

2021-03-18

·

Updated

2025-11-03

·

CVE-2021-28664

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Arm Mali Graphics Processing Unit (GPU) versions Bifrost r0p0 through r29p0 before r30p0 Arm Mali Graphics Processing Unit (GPU) versions Valhall r19p0 through r29p0 before r30p0 Arm Mali Graphics Processing Unit (GPU) versions Midgard r8p0 through r30p0 before r31p0
Description The issue is related to insufficient access control in the Arm Mali Graphics Processing Unit (GPU) driver, based on Midgard, Bifrost, and Valhall architectures. Exploitation of this issue may allow a remote attacker to escalate privileges, gain unauthorized access to protected information, or cause a denial of service. The vulnerability is due to an unprivileged user being able to achieve read/write access to read-only pages, potentially leading to memory corruption.
Recommendations For Bifrost r0p0 through r29p0 before r30p0, update to version r30p0 or later to resolve the issue. For Valhall r19p0 through r29p0 before r30p0, update to version r30p0 or later to resolve the issue. For Midgard r8p0 through r30p0 before r31p0, update to version r31p0 or later to resolve the issue. As a temporary workaround, consider restricting access to the kernel driver to minimize the risk of exploitation.

Fix

LPE

DoS

Buffer Overflow

Memory Corruption

Improper Privilege Management

Weakness Enumeration

Related Identifiers

ASB-A-174588870
BDU:2021-05815
CVE-2021-28664

Affected Products

Arm Mali Graphics Processing Unit