CVE-2021-28663
10.05.2021, 15:15
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| arm | bifrost_gpu_kernel_driver | r0p0 ≤ 𝑥 < r29p0 |
| arm | midgard_gpu_kernel_driver | r4p0 ≤ 𝑥 < r31p0 |
| arm | valhall_gpu_kernel_driver | r19p0 ≤ 𝑥 < r29p0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| arm | bifrost_gpu_kernel_driver | 𝑥 ≤ r28p0 | ADP |
| arm | valhall_gpu_kernel_driver | 𝑥 ≤ r28p0 | ADP |
| arm | midgard_gpu_kernel_driver | 𝑥 ≤ r30p0 | ADP |
Common Weakness Enumeration
References