CVE-2021-28664

The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:00

Type Values Removed Values Added
References () https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - Vendor Advisory () https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - Vendor Advisory
References () https://developer.arm.com/support/arm-security-updates - Vendor Advisory () https://developer.arm.com/support/arm-security-updates - Vendor Advisory
References () https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver - Vendor Advisory () https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver - Vendor Advisory

25 Jul 2024, 17:59

Type Values Removed Values Added
References () https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - () https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - Vendor Advisory

13 Dec 2023, 13:51

Type Values Removed Values Added
CPE cpe:2.3:a:arm:midguard_gpu_kernel_driver:*:*:*:*:*:*:*:* cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:*

27 Oct 2022, 21:15

Type Values Removed Values Added
Summary The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r8p0 through r30p0. The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
References
  • (MISC) https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities -

03 May 2022, 16:04

Type Values Removed Values Added
CWE CWE-269 CWE-787

17 Jun 2021, 14:50

Type Values Removed Values Added
CWE CWE-416

15 Jun 2021, 14:09

Type Values Removed Values Added
CPE cpe:2.3:a:arm:midguard_gpu_kernel_driver:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:*
cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 9.0
v3 : 8.8
References (CONFIRM) https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver - (CONFIRM) https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver - Vendor Advisory
References (MISC) https://developer.arm.com/support/arm-security-updates - (MISC) https://developer.arm.com/support/arm-security-updates - Vendor Advisory
CWE CWE-269
CWE-416

Information

Published : 2021-05-10 15:15

Updated : 2025-04-03 19:15


NVD link : CVE-2021-28664

Mitre link : CVE-2021-28664

CVE.ORG link : CVE-2021-28664


JSON object : View

Products Affected

arm

  • valhall_gpu_kernel_driver
  • bifrost_gpu_kernel_driver
  • midgard_gpu_kernel_driver
CWE
CWE-787

Out-of-bounds Write