← Back to CVE List
Vulnerability Intelligence Report
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

CVE-2021-29256

. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.8
HIGH
Exploitability:2.9
Impact Score:5.9
EPSS Probability:3.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-416 ↗CWE-416 Use After Free

Affected Products & Versions

Vendor Product Affected Versions
arm bifrost_gpu_kernel_driver all
arm midgard_gpu_kernel_driver all
arm valhall_gpu_kernel_driver all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
3.020%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-03-26T00:00:00
Published2021-05-24T17:56:27
Last Updated2025-10-21T23:25:45

LINK COPIED TO CLIPBOARD