FAIL › dossier
Arm
VENDOR· dossier confidence 60%
Arm Holdings, a key provider of microprocessor IP, has a concerning history of high-severity security vulnerabilities in its Mali GPU kernel drivers, frequently exploited and impacting a wide range of devices. These recurring issues, including use-after-free and information disclosure, highlight potential weaknesses in their development and testing processes, requiring immediate attention for CMMC compliance.
Arm has demonstrated a history of significant security vulnerabilities in its Mali GPU kernel drivers, frequently exploited in the wild. These vulnerabilities often involve use-after-free, information disclosure, and unauthorized memory access, indicating a potential weakness in their driver development and security testing processes.
- CVE-2023-4211: Mali GPU Kernel Driver Use-After-Free
- CVE-2023-26083: Mali GPU Kernel Driver Information Disclosure
- CVE-2022-38181: Mali GPU Kernel Driver RCE via Use-After-Free
- CVE-2022-22706: Mali GPU Kernel Driver Unauthorized Memory Write
- CVE-2021-27562: Mali GPU Use-After-Free, Local Privilege Escalation
- CVE-2021-28664: Mali GPU Kernel Driver Unspecified Vulnerability, Root Privilege Escalation
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2021-27562 | high | Arm Trusted Firmware's out-of-bounds write flaw allowed non-secure code to halt systems, overwrite secure data, or leak secrets, and was actively exploited in the wild. |
| 2021-11-03 | CVE-2021-28663 | high | An unpatched use-after-free flaw in Arm Mali GPUs allowed local privilege escalation to root, later appearing in CISA's KEV catalog. |
| 2021-11-03 | CVE-2021-28664 | high | An unspecified vulnerability in the Arm Mali GPU kernel driver allowed non-privileged users to gain root access, corrupt memory, and modify other processes. |
| 2023-10-03 | CVE-2023-4211 | high | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability |
| 2023-04-07 | CVE-2023-26083 | high | Arm Mali GPU Kernel Driver exposed sensitive kernel metadata due to an information disclosure vulnerability |
| 2023-03-30 | CVE-2022-38181 | high | Arm Mali GPU Kernel Driver exposed use-after-free, allowing root privilege escalation and info disclosure. |
| 2023-03-30 | CVE-2022-22706 | high | Arm Mali GPU Kernel Driver allows unauthorized write access to read-only memory pages. |
| 2024-06-12 | CVE-2024-4610 | high | Arm's Mali GPU kernel driver contains a high-severity use-after-free vulnerability actively exploited in the wild. |
| 2023-07-07 | CVE-2021-29256 | high | A use-after-free vulnerability in Arm Mali GPUs allowed local privilege escalation and information disclosure, and is currently being exploited in the wild. |
"Vendors List All Vendor TOP 100 Vendors with CVE"
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution"
"CISA sounds alarm over trio of exploited SharePoint flaws"
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
"This vulnerability affects Yealink Device Management servers."
"Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes."
"CISA urges immediate SharePoint hardening as exploits mount"
- Arm Holdings - Wikipedia · en.wikipedia.org
- Arm - 2026 Company Profile & Team - Tracxn · tracxn.com
- Company Profile · citiadr.factsetdigitalsolutions.com
- Whitepaper: Cybersecurity with Arm® TrustZone - Hitex GmbH · www.hitex.com
- Secure Coding Practices: From Vulnerabilities to a Secure Development ... · bridgeapp.ai
- arXiv: Vulnerability Detection in AArch64 Machine Code Us… — AI_SAFETY ... · matproof.com