Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
CVE-2021-29256EPSS 3.0%ArmMali Graphics Processing Unit (GPU)
Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata. Required action: Apply updates per vendor instructions.
CVE-2023-26083EPSS 1.4%ArmMali Graphics Processing Unit (GPU)
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. Required action: Apply updates per vendor instructions.
CVE-2022-38181EPSS 12.6%ArmMali Graphics Processing Unit (GPU)
Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages. Required action: Apply updates per vendor instructions.
CVE-2022-22706EPSS 1.2%ArmMali Graphics Processing Unit (GPU)
Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers. Required action: Apply updates per vendor instructions.
Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes. Required action: Apply updates per vendor instructions.
CVE-2021-28664EPSS 5.5%ArmMali Graphics Processing Unit (GPU)
Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information. Required action: Apply updates per vendor instructions.
CVE-2021-28663EPSS 12.1%ArmMali Graphics Processing Unit (GPU)