Vulnerability record · CVE-2021-44828 · published 14 January 2022
CVE-2021-44828: Arm bifrost gpu kernel driver out-of-bounds write vulnerability
Arm · Bifrost Gpu Kernel Driver
Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root privileges, corrupt memory, and modify the memory of other processes.
Description
Arm Mali GPU Kernel Driver (Midgard r26p0 through r30p0, Bifrost r0p0 through r34p0, and Valhall r19p0 through r34p0) allows a non-privileged user to achieve write access to read-only memory, and possibly obtain root privileges, corrupt memory, and modify the memory of other processes.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
Track CVE-2021-44828 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-44828), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.