Vulnerability record · CVE-2021-28663 · published 10 May 2021
CVE-2021-28663: Arm Mali GPU kernel driver use-after-free privilege escalation
Arm · Bifrost Gpu Kernel Driver
The Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker with low privileges can exploit this to escalate privileges or disclose information on affected devices.
Description
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8, CISA KEV listing and a public exploit reference indicate active exploitation risk despite the local privilege requirement.
What it is
The Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker with low privileges can exploit this to escalate privileges or disclose information on affected devices.
Impact
An attacker gains elevated privileges on the device or reads kernel memory, potentially leading to full system compromise.
Attack surface
Reached through the GPU kernel driver interface; the CVSS vector indicates network attack vector with low privileges required and no user interaction, though the flaw is a kernel driver memory issue typically triggered locally.
Exploitation
CVE-2021-28663 is listed in CISA KEV with a due date of 2021-11-17, and a public exploit reference exists; EPSS 30-day probability is 0.12084 (95.9th percentile).
What to do
- Apply the vendor security updates for the Mali GPU kernel driver per Arm advisories.
- Update to driver versions at or above r29p0 for Bifrost and Valhall, and the fixed Midgard release.
- Restrict local access and untrusted application execution on devices with affected Mali GPUs.
- Monitor vendor advisories for further patches and validate driver versions across fleets.
Detection
- Monitor for unexpected privilege escalation or anomalous GPU driver crashes on affected devices.
- Audit kernel logs for use-after-free related faults in the Mali driver.
- Track driver versions against the affected Bifrost, Valhall and Midgard ranges.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-28663 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://developer.arm.com/support/arm-security-updates | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://github.com/lntrx/CVE-2021-28663 | Exploit |
| https://developer.arm.com/support/arm-security-updates | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://github.com/lntrx/CVE-2021-28663 | Exploit |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28663 | US Government Resource |
Track CVE-2021-28663 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28663), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.