login
quiescence.eu
Saltar al contenido

CVE-2021-29256

Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

n/a
CVSS
3.0%
EPSS (exploit prob.)
86.0%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2023-07-07
Added

MITRE ATT&CK techniques

How this vulnerability maps to adversary behaviour, from the Center for Threat-Informed Defense's public CVE→ATT&CK mappings. Use it to check whether your detections already cover the technique.

TechniqueNameRelationship
T1203 Exploitation for Client Execution exploitation technique
T1068 Exploitation for Privilege Escalation primary impact
T1005 Data from Local System secondary impact

Summary

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

Affected software

Vendor: Arm  ·  Product: Mali Graphics Processing Unit (GPU)

Weakness types (CWE):

CWE-416

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in Arm

CVENameEPSSExploited
CVE-2022-38181 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 12.6% Yes
CVE-2021-28663 Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability 12.1% Yes
CVE-2021-28664 Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability 5.5% Yes
CVE-2021-27562 Arm Trusted Firmware Out-of-Bounds Write Vulnerability 3.1% Yes
CVE-2023-26083 Arm Mali GPU Kernel Driver Information Disclosure Vulnerability 1.4% Yes
CVE-2023-4211 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 1.4% Yes
CVE-2022-22706 Arm Mali GPU Kernel Driver Unspecified Vulnerability 1.2% Yes
CVE-2024-4610 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability 0.8% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.