← Vulnerability feed

Vulnerability record · CVE-2021-28664 · published 10 May 2021

CVE-2021-28664: Arm Mali GPU kernel driver out-of-bounds write allows privilege escalation

Arm · Bifrost Gpu Kernel Driver

The Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privilege escalation or denial of service on affected Bifrost, Valhall and Midgard driver versions. It matters because the flaw is reachable by a local unprivileged user and has been exploited in the wild.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 5.4% · top 7.6% CWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 9.0
5.4%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 with confirmed KEV exploitation and high EPSS percentile, though no ransomware use is documented.

What it is

The Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privilege escalation or denial of service on affected Bifrost, Valhall and Midgard driver versions. It matters because the flaw is reachable by a local unprivileged user and has been exploited in the wild.

Impact

An attacker gains read/write access to memory that should be read-only, enabling privilege escalation to kernel or elevated context, or crashing the system for denial of service.

Attack surface

Reached through the Mali GPU kernel driver interface; the CVSS vector indicates network attack vector with low privileges required and no user interaction, though the description frames the trigger as an unprivileged local user. No authentication beyond low privilege is needed.

Exploitation

Listed in CISA KEV with a 2021-11-03 addition and 2021-11-17 remediation due date, confirming known exploitation. EPSS 30-day probability is 0.05407 (92.3rd percentile), and references are vendor advisories plus the KEV entry.

What to do

  • Apply the Arm Mali GPU kernel driver updates referenced in the vendor security advisories, moving to r30p0 or later for Bifrost/Valhall and r31p0 or later for Midgard.
  • Track the CISA KEV due date and confirm remediation across all affected devices.
  • Restrict or monitor access to GPU driver interfaces for unprivileged users where feasible.
  • Inventory devices using Arm Mali Bifrost, Valhall or Midgard GPU drivers to find unpatched units.

Detection

  • Monitor for unexpected kernel memory corruption or GPU driver crashes on affected devices.
  • Watch for privilege escalation attempts or anomalous processes gaining elevated access after GPU driver activity.
  • Audit systems for Mali GPU driver versions below the fixed releases.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-28664 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-28664 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38181Arm Mali GPU kernel driver use-after-free via mishandled GPU memory operationsThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affe…KEVEPSS 14%analysed8.8CVE-2021-29256Arm Mali GPU kernel driver use-after-free allows privilege escalationThe Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitat…KEVEPSS 3.0%analysed8.8CVE-2021-28663Arm Mali GPU kernel driver use-after-free privilege escalationThe Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker…KEVEPSS 12%analysed7.8CVE-2024-4610Arm Mali GPU kernel driver use-after-free lets local user access freed memoryThe Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU me…KEVEPSS 0.76%analysed7.8CVE-2022-22706Arm Mali GPU Kernel Driver read-only memory write flawThe Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting M…KEVEPSS 1.1%analysed5.5CVE-2023-4211Arm Mali GPU Kernel Driver use-after-free via improper GPU memory handlingThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A l…KEVEPSS 1.1%analysed3.3CVE-2023-26083Arm Mali GPU Kernel Driver memory leak exposes kernel metadataThe Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0…KEVEPSS 1.2%analysed9.8CVE-2022-28349Arm bifrost gpu kernel driver use after free vulnerabilityArm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-28664), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.