← All CVEs

CVE-2021-29256

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Added 2023-07-07Remediation due 2023-07-28

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

8.8
CVSS
3.0%
EPSS (exploit prob.)
87th
EPSS percentile
2021-05-24
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-416

Affected products

VendorProductAffected versions
armbifrost_gpu_kernel_driver>= r16p0, < r30p0
armmidgard_gpu_kernel_driver>= r28p0, < r31p0
armvalhall_gpu_kernel_driver>= r19p0, < r30p0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-29256