EXPOSURES › CVE-2021-28663
CVE-2021-28663
HIGH ⌖ ON CISA KEV · EXPLOITEDAn unpatched use-after-free flaw in Arm Mali GPUs allowed local privilege escalation to root, later appearing in CISA's KEV catalog.
The Arm Mali GPU kernel driver contained a use-after-free vulnerability enabling local users to escalate privileges to root or leak data. DIB organizations must ensure GPU drivers are patched to prevent local-to-root escalation, which can serve as a foothold for lateral movement or data exfiltration. This flaw was actively exploited in the wild and added to CISA's KEV catalog, indicating it was successfully leveraged by threat actors.
Shame score — The vulnerability was unpatched for a significant period, was actively exploited in the wild, and allowed local privilege escalation to root, representing a severe and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.