peter bassill · operator
$ cve CVE-2021-29256 JSON

CVE-2021-29256 KEV

8.8
HIGH · CVSS 3.1 · EPSS 3% (pctl 87)

Patch first

On CISA KEV — known exploited in the wild, due 2023-07-28.

Description

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS2.99% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2023-07-28
Public exploitnone known
Published2021-05-24
Last modified2026-06-17

CISA KEV

NameArm Mali GPU Kernel Driver Use-After-Free Vulnerability
Added2023-07-07
Due2023-07-28
Vendor / productArm / Mali Graphics Processing Unit (GPU)
Ransomware usenone reported

Affected (3)

VendorProduct
armbifrost gpu kernel driver
armmidgard gpu kernel driver
armvalhall gpu kernel driver

References

→ the Explorer  ·  watch your stack  ·  NVD