CVE-2021-29256
KEVmassUse-After-Free in Arm Mali GPU Kernel Driver Allows Root Privilege Escalation
CISA: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
The Arm Mali GPU kernel driver (Bifrost, Valhall, and Midgard variants) contains a use-after-free flaw (CWE-416) that allows an unprivileged user to access freed kernel memory. An attacker triggers the bug from a low-privileged process on a device running a vulnerable Mali driver revision, and gains information disclosure and, in many cases, root privilege escalation. Affected ranges are Bifrost r16p0 through r29p0, Valhall r19p0 through r29p0, and Midgard r28p0 through r30p0, which are deployed across a very large base of Android smartphones, tablets, TV boxes, and other embedded devices. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-07-07), indicating observed exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available. EPSS assigns a 3.0% probability of exploitation in the next 30 days (87th percentile).
What to do: Upgrade the Mali GPU kernel driver: Bifrost and Valhall to r30p0 or later, and Midgard to a release later than r30p0, or apply the equivalent patch delivered by your SoC/OS vendor (e.g., Android security bulletin updates, as referenced in recent Google patch releases). Check the Mali driver revision on affected devices and prioritize patching because the flaw is on CISA's KEV list as actively exploited. As an interim mitigation, avoid running untrusted local code on devices that still run vulnerable Mali driver versions.
| Arm Mali Bifrost GPU kernel driver | r16p0 through r29p0 (before r30p0) |
| Arm Mali Valhall GPU kernel driver | r19p0 through r29p0 (before r30p0) |
| Arm Mali Midgard GPU kernel driver | r28p0 through r30p0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
- Affected
- Arm Mali Graphics Processing Unit (GPU)
- Required action
- Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- arm
- Products
- bifrost gpu kernel driver, midgard gpu kernel driver, valhall gpu kernel driver
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H