Vulnerability record · CVE-2021-28664 · published 10 May 2021
CVE-2021-28664: Arm Mali GPU kernel driver out-of-bounds write allows privilege escalation
Arm · Bifrost Gpu Kernel Driver
The Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privilege escalation or denial of service on affected Bifrost, Valhall and Midgard driver versions. It matters because the flaw is reachable by a local unprivileged user and has been exploited in the wild.
Description
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with confirmed KEV exploitation and high EPSS percentile, though no ransomware use is documented.
What it is
The Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privilege escalation or denial of service on affected Bifrost, Valhall and Midgard driver versions. It matters because the flaw is reachable by a local unprivileged user and has been exploited in the wild.
Impact
An attacker gains read/write access to memory that should be read-only, enabling privilege escalation to kernel or elevated context, or crashing the system for denial of service.
Attack surface
Reached through the Mali GPU kernel driver interface; the CVSS vector indicates network attack vector with low privileges required and no user interaction, though the description frames the trigger as an unprivileged local user. No authentication beyond low privilege is needed.
Exploitation
Listed in CISA KEV with a 2021-11-03 addition and 2021-11-17 remediation due date, confirming known exploitation. EPSS 30-day probability is 0.05407 (92.3rd percentile), and references are vendor advisories plus the KEV entry.
What to do
- Apply the Arm Mali GPU kernel driver updates referenced in the vendor security advisories, moving to r30p0 or later for Bifrost/Valhall and r31p0 or later for Midgard.
- Track the CISA KEV due date and confirm remediation across all affected devices.
- Restrict or monitor access to GPU driver interfaces for unprivileged users where feasible.
- Inventory devices using Arm Mali Bifrost, Valhall or Midgard GPU drivers to find unpatched units.
Detection
- Monitor for unexpected kernel memory corruption or GPU driver crashes on affected devices.
- Watch for privilege escalation attempts or anomalous processes gaining elevated access after GPU driver activity.
- Audit systems for Mali GPU driver versions below the fixed releases.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-28664 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-28664 | US Government Resource |
Track CVE-2021-28664 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28664), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.