CVE-2021-28663 is a critical use-after-free vulnerability in the Arm Mali GPU kernel driver, affecting Bifrost, Valhall, and Midgard GPU versions. This flaw allows for privilege escalation or information disclosure due to mishandled GPU memory operations. With a CVSS score of 8.8 (HIGH), it presents a significant risk, allowing unauthenticated attackers to achieve high confidentiality, integrity, and availability impacts with low attack complexity. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and extensive media coverage, despite no public exploit code being readily available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r0p0, < r29p0CPE matchmatch criteria | cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r4p0, < r31p0CPE matchmatch criteria | cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r19p0, < r29p0CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.