High severity8.8CISA KEVNVD Advisory· Published May 10, 2021· Updated Jun 17, 2026
CVE-2021-28663
CVE-2021-28663
Description
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:*Range: >=r0p0,<r29p0
- cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:*Range: >=r4p0,<r31p0
- cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:*Range: >=r19p0,<r29p0
- Arm/Arm Mali GPU kernel driverdescription
- Range: Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0
Patches
Vulnerability mechanics
References
3- developer.arm.com/support/arm-security-updatesnvdVendor Advisory
- developer.arm.com/support/arm-security-updates/mali-gpu-kernel-drivernvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.