CVE-2021-28663

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
10/05/2021
Last modified:
14/03/2025

Description

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* r0p0 (including) r29p0 (excluding)
cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:* r4p0 (including) r31p0 (excluding)
cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* r19p0 (including) r29p0 (excluding)