{"cveID":"CVE-2021-29256","vendorProject":"Arm","product":"Mali Graphics Processing Unit (GPU)","vulnerabilityName":"Arm Mali GPU Kernel Driver Use-After-Free Vulnerability","dateAdded":"2023-07-07","shortDescription":"Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.","requiredAction":"Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.","dueDate":"2023-07-28","knownRansomwareCampaignUse":"Unknown","notes":"https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities; https://nvd.nist.gov/vuln/detail/CVE-2021-29256","cwes":["CWE-416"],"year":2021,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2021-29256","technique":"T1203","technique_name_at_mapping":"Exploitation for Client Execution","mapping_type":"exploitation_technique","capability_group":"use_after_free","comments":"This vulnerability is exploited by an unprivileged attacker by conducting malicious activity in GPU memory, gaining access to already freed memory. If successful, the threat actor could escalate their privileges to root as well as gain access to sensitive information. Detailed information about how adversaries exploit the GPU are not publicly available. ","references":["https://vuldb.com/?id.175586","https://www.tenable.com/plugins/nessus/178128","https://www.lexology.com/library/detail.aspx?g=c57b19cd-73e4-43e2-8034-f7fa78166c63","https://source.android.com/docs/security/bulletin/2023-07-01#arm-components","https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2023-072"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-29256","technique":"T1005","technique_name_at_mapping":"Data from Local System","mapping_type":"secondary_impact","capability_group":"use_after_free","comments":"This vulnerability is exploited by an unprivileged attacker by conducting malicious activity in GPU memory, gaining access to already freed memory. If successful, the threat actor could escalate their privileges to root as well as gain access to sensitive information. Detailed information about how adversaries exploit the GPU are not publicly available. ","references":["https://vuldb.com/?id.175586","https://www.tenable.com/plugins/nessus/178128","https://www.lexology.com/library/detail.aspx?g=c57b19cd-73e4-43e2-8034-f7fa78166c63","https://source.android.com/docs/security/bulletin/2023-07-01#arm-components","https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2023-072"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2021-29256","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"primary_impact","capability_group":"use_after_free","comments":"This vulnerability is exploited by an unprivileged attacker by conducting malicious activity in GPU memory, gaining access to already freed memory. If successful, the threat actor could escalate their privileges to root as well as gain access to sensitive information. Detailed information about how adversaries exploit the GPU are not publicly available. ","references":["https://vuldb.com/?id.175586","https://www.tenable.com/plugins/nessus/178128","https://www.lexology.com/library/detail.aspx?g=c57b19cd-73e4-43e2-8034-f7fa78166c63","https://source.android.com/docs/security/bulletin/2023-07-01#arm-components","https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-android-os-could-allow-for-remote-code-execution_2023-072"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Local System","name_at_mapping":"Data from Local System","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1203","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Client Execution","name_at_mapping":"Exploitation for Client Execution","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":35,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}