CVE-2021-29256 KEV
8.8
HIGH · CVSS 3.1 · EPSS 3% (pctl 87)
Patch first
On CISA KEV — known exploited in the wild, due 2023-07-28.
Description
. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.99% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2023-07-28 |
| Public exploit | none known |
| Published | 2021-05-24 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability |
|---|---|
| Added | 2023-07-07 |
| Due | 2023-07-28 |
| Vendor / product | Arm / Mali Graphics Processing Unit (GPU) |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| arm | bifrost gpu kernel driver |
| arm | midgard gpu kernel driver |
| arm | valhall gpu kernel driver |
References
→ the Explorer · watch your stack · NVD