CVE-2021-28663: Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability
Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.
Other sources
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28663?
CVE-2021-28663 is a use-after-free vulnerability in the Arm Mali GPU kernel driver that allows privilege escalation or information disclosure.
Which software is affected by CVE-2021-28663?
CVE-2021-28663 affects Arm Mali Graphics Processing Unit (GPU) and Android.
What is the severity of CVE-2021-28663?
The severity of CVE-2021-28663 is critical, with a CVSS score of 8.8.
How can CVE-2021-28663 be exploited?
CVE-2021-28663 can be exploited by mishandling GPU memory operations, leading to a use-after-free vulnerability.
How can I fix CVE-2021-28663?
To fix CVE-2021-28663, update the Arm Mali GPU kernel driver to a version later than r29p0 for Bifrost, Valhall, and Midgard.