ZeroHour

CVE-2021-29256

KEVmass

Use-After-Free in Arm Mali GPU Kernel Driver Allows Root Privilege Escalation

CISA: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
3%p87
Published
()
KEV added
AI analysis

The Arm Mali GPU kernel driver (Bifrost, Valhall, and Midgard variants) contains a use-after-free flaw (CWE-416) that allows an unprivileged user to access freed kernel memory. An attacker triggers the bug from a low-privileged process on a device running a vulnerable Mali driver revision, and gains information disclosure and, in many cases, root privilege escalation. Affected ranges are Bifrost r16p0 through r29p0, Valhall r19p0 through r29p0, and Midgard r28p0 through r30p0, which are deployed across a very large base of Android smartphones, tablets, TV boxes, and other embedded devices. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-07-07), indicating observed exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available. EPSS assigns a 3.0% probability of exploitation in the next 30 days (87th percentile).

What to do: Upgrade the Mali GPU kernel driver: Bifrost and Valhall to r30p0 or later, and Midgard to a release later than r30p0, or apply the equivalent patch delivered by your SoC/OS vendor (e.g., Android security bulletin updates, as referenced in recent Google patch releases). Check the Mali driver revision on affected devices and prioritize patching because the flaw is on CISA's KEV list as actively exploited. As an interim mitigation, avoid running untrusted local code on devices that still run vulnerable Mali driver versions.

Affected
Arm Mali Bifrost GPU kernel driverr16p0 through r29p0 (before r30p0)
Arm Mali Valhall GPU kernel driverr19p0 through r29p0 (before r30p0)
Arm Mali Midgard GPU kernel driverr28p0 through r30p0
Estimated exposure
masshundreds of millions of devices (Mali GPUs are integrated in a large share of Android and embedded SoCs) — Estimate based on the enormous installed base of Mali-GPU-equipped Android and embedded devices (e.g., MediaTek and Amlogic SoCs), with only devices running the affected driver revisions r16 through r30-era actually vulnerable.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

CISA Known Exploited Vulnerability
Affected
Arm Mali Graphics Processing Unit (GPU)
Required action
Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Due date
Ransomware use
Unknown
Vendors
arm
Products
bifrost gpu kernel driver, midgard gpu kernel driver, valhall gpu kernel driver
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news