CVE-2021-28663
arm bifrost_gpu_kernel_driver, arm valhall_gpu_kernel_driver, arm midgard_gpu_kernel_driver
Published 10 May 2021 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 17 Nov 2021 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
References
- developer.arm.com/support/arm-security-updates · Vendor Advisory
- developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver · Vendor Advisory
- github.com/lntrx/CVE-2021-28663 · Exploit
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28663 · US Government Resource