← Vulnerability feed

Vulnerability record · CVE-2021-29256 · published 24 May 2021

CVE-2021-29256: Arm Mali GPU kernel driver use-after-free allows privilege escalation

Arm · Bifrost Gpu Kernel Driver

The Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitation leads to information disclosure or escalation to root. It affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

8.8 CVSS 3.1 High CISA KEV since 7 Jul 2023 EPSS 3.0% · top 13.2% CWE-416 · Use after free
8.8CVSS 3.1 base score, v2 9.0
3.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 with confirmed in-the-wild exploitation per CISA KEV, though EPSS probability is relatively low.

What it is

The Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitation leads to information disclosure or escalation to root. It affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

Impact

An attacker gains access to freed kernel memory, which can disclose sensitive data or allow escalation to root privileges on the affected device.

Attack surface

The flaw is reachable by an unprivileged local user through the GPU kernel driver; the CVSS vector (AV:N/AC:L/PR:L/UI:N) indicates network-reachable attack with low privileges and no user interaction, though the description frames it as an unprivileged-user local condition.

Exploitation

CVE-2021-29256 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-07-07), confirming exploitation in the wild; EPSS 30-day probability is 0.02988 (86.6th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor fix by upgrading Mali GPU kernel drivers to r30p0 or later for Bifrost, Valhall, and Midgard as applicable.
  • If patching is not possible, discontinue use of affected products per CISA guidance.
  • Restrict local unprivileged access to GPU device nodes where feasible.
  • Track vendor advisories for updated driver releases and backports.

Detection

  • Monitor for unexpected privilege escalation or root-level process creation on devices with Mali GPUs.
  • Watch for crashes or anomalous GPU driver behavior that may indicate use-after-free triggering.
  • Audit access to GPU device nodes by unprivileged users.
  • Correlate with CISA KEV remediation deadlines for affected assets.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-29256 to the Known Exploited Vulnerabilities catalog on 7 July 2023 as "Arm Mali GPU Kernel Driver Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 28 July 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-29256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38181Arm Mali GPU kernel driver use-after-free via mishandled GPU memory operationsThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affe…KEVEPSS 14%analysed8.8CVE-2021-28663Arm Mali GPU kernel driver use-after-free privilege escalationThe Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker…KEVEPSS 12%analysed8.8CVE-2021-28664Arm Mali GPU kernel driver out-of-bounds write allows privilege escalationThe Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privi…KEVEPSS 5.4%analysed7.8CVE-2024-4610Arm Mali GPU kernel driver use-after-free lets local user access freed memoryThe Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU me…KEVEPSS 0.76%analysed7.8CVE-2022-22706Arm Mali GPU Kernel Driver read-only memory write flawThe Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting M…KEVEPSS 1.1%analysed5.5CVE-2023-4211Arm Mali GPU Kernel Driver use-after-free via improper GPU memory handlingThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A l…KEVEPSS 1.1%analysed3.3CVE-2023-26083Arm Mali GPU Kernel Driver memory leak exposes kernel metadataThe Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0…KEVEPSS 1.2%analysed9.8CVE-2022-28349Arm bifrost gpu kernel driver use after free vulnerabilityArm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-29256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.