{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2021-29256",
  "revision": 1,
  "title": "Arm Mali driver — freed memory, or root",
  "summary": "The Arm graphics driver (GPU) lets an unprivileged user reach memory that was already released, which yields either disclosed data or root on the device. Bifrost, Valhall and Midgard driver ranges before r30p0 are affected.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 8.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.02988,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-07-07",
    "prerequisites": "The attacker needs to run unprivileged code on the device."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1068"
  ],
  "kill_chain": "privilege_escalation",
  "recommended_action": "Take the r30p0 driver or later from Arm, or the handset build carrying it. Devices whose vendor stopped shipping updates keep this one for good.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-29256",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2021-29256",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2021-29256",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-29256",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver"
    }
  ],
  "published_at": "2021-05-24T18:15:08.033Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "arm",
    "mali",
    "gpu",
    "driver",
    "use-after-free",
    "mobile",
    "kev"
  ]
}
