Skip to content
COOEY

FAIL › dossier

Mali Graphics Processing Unit (GPU)

PRODUCT

· dossier confidence 20%

Mali GPUs are a foundational component in mobile and embedded devices, but their kernel driver has a history of severe, recurring security flaws. These include use-after-free bugs, memory corruption, and information disclosure vulnerabilities that have been actively exploited in the wild, indicating a need for rigorous security testing and patching processes.

PROFILE
CategorysemiconductorWhat they doMali is a family of graphics processing units (GPUs) designed by Arm Holdings for mobile and embedded devices. Websitehttps://developer.arm.com/ ↗
SECURITY POSTURE

The Arm Mali GPU driver has a poor security track record, with repeated high-severity vulnerabilities including use-after-free bugs, information disclosure, and memory corruption flaws that have been actively exploited in the wild.

Notable failures
  • CVE-2025-0072: Bypasses MTE and enables arbitrary kernel code execution
  • CVE-2023-26083: Information disclosure exposing sensitive kernel metadata
  • CVE-2022-38181: Use-after-free allowing root privilege escalation
Patterns: repeated use-after-free vulnerabilities in the kernel driver; information disclosure exposing kernel metadata; memory corruption allowing unauthorized write access to read-only memory
FAILURE HISTORY · 6
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2021-28664 high An unspecified vulnerability in the Arm Mali GPU kernel driver allowed non-privileged users to gain root access, corrupt memory, and modify other processes.
2021-11-03 CVE-2021-28663 high An unpatched use-after-free flaw in Arm Mali GPUs allowed local privilege escalation to root, later appearing in CISA's KEV catalog.
2023-04-07 CVE-2023-26083 high Arm Mali GPU Kernel Driver exposed sensitive kernel metadata due to an information disclosure vulnerability
2023-03-30 CVE-2022-38181 high Arm Mali GPU Kernel Driver exposed use-after-free, allowing root privilege escalation and info disclosure.
2023-03-30 CVE-2022-22706 high Arm Mali GPU Kernel Driver allows unauthorized write access to read-only memory pages.
2023-07-07 CVE-2021-29256 high A use-after-free vulnerability in Arm Mali GPUs allowed local privilege escalation and information disclosure, and is currently being exploited in the wild.
Open questions: Are there any web sources confirming Arm Holdings' current security response to these CVEs? · What is the current patching cadence for Arm Mali GPU kernel drivers?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-09 04:56:45.233223+00:00