CVE-2021-28664
arm bifrost gpu kernel driver, arm midgard gpu kernel driver, arm valhall gpu kernel driver
Published 10 May 2021 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 17 Nov 2021 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
References
- developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities · Vendor Advisory
- developer.arm.com/support/arm-security-updates · Vendor Advisory
- developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28664 · US Government Resource