Vulnerability record · CVE-2021-29256 · published 24 May 2021
CVE-2021-29256: Arm Mali GPU kernel driver use-after-free allows privilege escalation
Arm · Bifrost Gpu Kernel Driver
The Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitation leads to information disclosure or escalation to root. It affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
Description
. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with confirmed in-the-wild exploitation per CISA KEV, though EPSS probability is relatively low.
What it is
The Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitation leads to information disclosure or escalation to root. It affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
Impact
An attacker gains access to freed kernel memory, which can disclose sensitive data or allow escalation to root privileges on the affected device.
Attack surface
The flaw is reachable by an unprivileged local user through the GPU kernel driver; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates network-reachable attack with low privileges and no user interaction, though the description frames it as an unprivileged-user local condition.
Exploitation
CVE-2021-29256 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-07-07), confirming exploitation in the wild; EPSS 30-day probability is 0.02988 (86.6th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor fix by upgrading Mali GPU kernel drivers to r30p0 or later for Bifrost, Valhall, and Midgard as applicable.
- If patching is not possible, discontinue use of affected products per CISA guidance.
- Restrict local unprivileged access to GPU device nodes where feasible.
- Track vendor advisories for updated driver releases and backports.
Detection
- Monitor for unexpected privilege escalation or root-level process creation on devices with Mali GPUs.
- Watch for crashes or anomalous GPU driver behavior that may indicate use-after-free triggering.
- Audit access to GPU device nodes by unprivileged users.
- Correlate with CISA KEV remediation deadlines for affected assets.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-29256 to the Known Exploited Vulnerabilities catalog on 7 July 2023 as "Arm Mali GPU Kernel Driver Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 28 July 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-29256 | US Government Resource |
Track CVE-2021-29256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.