LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-29256: Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 7, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 28, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-29256 to its Known Exploited Vulnerabilities catalog on Jul 7, 2023, with a federal patch deadline of Jul 28, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

CVE-2021-29256 is a use-after-free flaw in the Arm Mali GPU kernel driver. It can let a non-privileged local user escalate to root privileges or disclose information. For IT and security teams managing Android devices, embedded systems, or any platforms that ship Arm Mali graphics hardware, this matters because kernel-level access can undermine device integrity, enable further compromise, and expose sensitive data. Confirm all product and version details against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-416, a use-after-free condition. In a use-after-free flaw, memory that has already been freed is later accessed again. When this occurs inside a kernel driver, an attacker who can trigger the condition from user space may corrupt kernel memory structures. According to the CISA summary, a non-privileged user can exploit this in the Arm Mali GPU kernel driver to gain root privilege and/or disclose information. Exact trigger conditions, memory objects involved, and exploitation steps are not detailed in the public summary; treat any such claims as unconfirmed until verified against the vendor advisory. The practical risk is local privilege escalation on systems where untrusted code can interact with the Mali driver.

Am I affected? How to find it in your systems

Arm Mali GPUs appear in many mobile handsets, tablets, set-top boxes, automotive systems, and other embedded Linux or Android platforms. The vulnerable component is the associated kernel driver, not the GPU silicon itself. Inventory steps include:

Telemetry signs of exploitation are not specifically documented. In general, watch for unexpected local privilege escalations, anomalous kernel oops or panics involving Mali symbols, sudden root processes spawned by unprivileged users, or unusual access to GPU device nodes. Correlate these with process and audit logs; absence of such signals does not prove safety.

How to remediate

Patch first. Apply the updates provided by Arm or by the device OEM exactly as instructed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions or discontinue use of the product if updates are unavailable. After patching:

Document the change and re-scan the inventory to confirm coverage.

If you can't patch immediately

Until a vendor update can be applied, reduce exposure with compensating controls:

These measures lower likelihood and impact but do not eliminate the underlying use-after-free condition.

If your data may have been exposed

Actively exploited kernel vulnerabilities can lead to full device compromise and subsequent data exposure. Known ransomware use of this CVE is not documented. If you suspect systems were reachable by untrusted local users before patching, treat them as potentially compromised: isolate, collect forensic images, rotate credentials that may have been present, and review access logs. Separately, you can run a free exposure scan of your email address to check whether it appears in known breach data sets and take appropriate credential-hygiene steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArm · Mali Graphics Processing Unit (GPU)
WeaknessCWE-416
Added to CISA KEVJul 7, 2023
Federal patch deadlineJul 28, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities