Skip to content
COOEY

FAIL › dossier

Arm

VENDOR

· dossier confidence 60%

Arm Holdings, a key provider of microprocessor IP, has a concerning history of high-severity security vulnerabilities in its Mali GPU kernel drivers, frequently exploited and impacting a wide range of devices. These recurring issues, including use-after-free and information disclosure, highlight potential weaknesses in their development and testing processes, requiring immediate attention for CMMC compliance.

PROFILE
CategorySemiconductor Design & LicensingWhat they doArm Holdings designs and licenses microprocessor architectures and related technologies. They provide intellectual property (IP) for various devices, including smartphones, servers, and automotive systems.Founded1990HQCambridge, UK Websitehttps://www.arm.com/ ↗
SECURITY POSTURE

Arm has demonstrated a history of significant security vulnerabilities in its Mali GPU kernel drivers, frequently exploited in the wild. These vulnerabilities often involve use-after-free, information disclosure, and unauthorized memory access, indicating a potential weakness in their driver development and security testing processes.

Notable failures
  • CVE-2023-4211: Mali GPU Kernel Driver Use-After-Free
  • CVE-2023-26083: Mali GPU Kernel Driver Information Disclosure
  • CVE-2022-38181: Mali GPU Kernel Driver RCE via Use-After-Free
  • CVE-2022-22706: Mali GPU Kernel Driver Unauthorized Memory Write
  • CVE-2021-27562: Mali GPU Use-After-Free, Local Privilege Escalation
  • CVE-2021-28664: Mali GPU Kernel Driver Unspecified Vulnerability, Root Privilege Escalation
Patterns: Recurring use-after-free vulnerabilities in Mali GPU kernel drivers; Information disclosure vulnerabilities exposing kernel metadata; Vulnerabilities leading to root privilege escalation; Active exploitation of vulnerabilities in the wild
Reputationsevere-fallout (-0.19) · 15 trusted sources CoverageThe Register · cooey · cooey · cooey · cve.armis.com · cvedb.shodan.io
FAILURE HISTORY · 9
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-27562 high Arm Trusted Firmware's out-of-bounds write flaw allowed non-secure code to halt systems, overwrite secure data, or leak secrets, and was actively exploited in the wild.
2021-11-03 CVE-2021-28663 high An unpatched use-after-free flaw in Arm Mali GPUs allowed local privilege escalation to root, later appearing in CISA's KEV catalog.
2021-11-03 CVE-2021-28664 high An unspecified vulnerability in the Arm Mali GPU kernel driver allowed non-privileged users to gain root access, corrupt memory, and modify other processes.
2023-10-03 CVE-2023-4211 high Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
2023-04-07 CVE-2023-26083 high Arm Mali GPU Kernel Driver exposed sensitive kernel metadata due to an information disclosure vulnerability
2023-03-30 CVE-2022-38181 high Arm Mali GPU Kernel Driver exposed use-after-free, allowing root privilege escalation and info disclosure.
2023-03-30 CVE-2022-22706 high Arm Mali GPU Kernel Driver allows unauthorized write access to read-only memory pages.
2024-06-12 CVE-2024-4610 high Arm's Mali GPU kernel driver contains a high-severity use-after-free vulnerability actively exploited in the wild.
2023-07-07 CVE-2021-29256 high A use-after-free vulnerability in Arm Mali GPUs allowed local privilege escalation and information disclosure, and is currently being exploited in the wild.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
Arm faced significant criticism and concern due to the severity of the vulnerability and its potential impact.
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
Widespread concern and active exploitation highlighted the severity of the vulnerability.
www.cvefind.com ↗severe-fallout+0.00
Provides context and lists Arm among vendors.
"Vendors List All Vendor TOP 100 Vendors with CVE"
cvefeed.io ↗severe-fallout-0.70
Highlights active exploitation, indicating a serious issue.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
cybersecuritynews.com ↗severe-fallout+0.00
Focuses on SharePoint vulnerabilities, not Arm.
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution"
The Register ↗severe-fallout+0.00
Focuses on SharePoint vulnerabilities, not Arm.
"CISA sounds alarm over trio of exploited SharePoint flaws"
cvedb.shodan.io ↗severe-fallout+0.00
Provides API information, no sentiment.
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
cooey ↗severe-fallout-0.80
Neutral reporting, highlighting impact.
"This vulnerability affects Yealink Device Management servers."
www.cvefind.com ↗severe-fallout+0.00
Neutral, descriptive listing.
xposedornot.com ↗severe-fallout+0.00
Neutral, descriptive listing.
cve.armis.com ↗severe-fallout+0.00
Neutral, promotional content.
cvefeed.io ↗severe-fallout+0.00
Neutral, descriptive listing.
cvedb.shodan.io ↗severe-fallout+0.00
Neutral, technical description.
securityonline.info ↗severe-fallout+0.00
Neutral, reporting on CVE statistics.
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-0.60
Neutral description of the vulnerability.
"Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes."
www.csoonline.com ↗severe-fallout+0.00
Focuses on SharePoint vulnerabilities, not Arm.
"CISA urges immediate SharePoint hardening as exploits mount"
Open questions: What specific security development practices are in place to prevent similar vulnerabilities? · What is the process for vulnerability disclosure and remediation? · How are licensees informed of and remediated for these vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-08 04:09:34.750443+00:00