CVE-2021-29256
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 28 July 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.99% probability · 87th percentile
- CISA KEV
- Listed 7 July 2023 · due 28 July 2023
- Weakness
- CWE-416
- Affected
- arm/bifrost gpu kernel driver · arm/midgard gpu kernel driver · arm/valhall gpu kernel driver
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2021-29256
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.