CVE-2021-28663
Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
YesDecision
Descriptions
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
El controlador del kernel de Arm Mali GPU, permite una escalada de privilegios o una divulgación de información porque las operaciones de la memoria de la GPU son manejadas inapropiadamente, conllevando a un uso de la memoria previamente liberada. Esto afecta a Bifrost versiones r0p0 hasta r28p0, anteriores a r29p0, Valhall versiones r19p0 hasta r28p0 anteriores a r29p0 y Midgard versiones r4p0 hasta r30p0
Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2021-03-18 CVE Reserved
- 2021-05-10 CVE Published
- 2021-11-03 Exploited in Wild
- 2021-11-17 KEV Due Date
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-09-12 EPSS Updated
CWE
- CWE-416: Use After Free
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/lntrx/CVE-2021-28663 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://developer.arm.com/support/arm-security-updates | 2023-12-13 | |
https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | 2023-12-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arm Search vendor "Arm" | Bifrost Gpu Kernel Driver Search vendor "Arm" for product "Bifrost Gpu Kernel Driver" | >= r0p0 <= r28p0 Search vendor "Arm" for product "Bifrost Gpu Kernel Driver" and version " >= r0p0 <= r28p0" | - |
Affected
| ||||||
Arm Search vendor "Arm" | Midgard Gpu Kernel Driver Search vendor "Arm" for product "Midgard Gpu Kernel Driver" | >= r4p0 <= r30p0 Search vendor "Arm" for product "Midgard Gpu Kernel Driver" and version " >= r4p0 <= r30p0" | - |
Affected
| ||||||
Arm Search vendor "Arm" | Valhall Gpu Kernel Driver Search vendor "Arm" for product "Valhall Gpu Kernel Driver" | >= r19p0 <= r28p0 Search vendor "Arm" for product "Valhall Gpu Kernel Driver" and version " >= r19p0 <= r28p0" | - |
Affected
|