Arm Mali GPU is exposed to rights loopholes, CISA urges Android users to upgrade as soon as possible
CTOnews.com July 9 news, the US Cyber Security and Infrastructure Security Agency (CISA) issued an announcement today, requiring Android users of US federal agencies to install patches within 3 weeks to fix the privilege escalation vulnerability that exists in the Mali GPU core of the Arm architecture.
The vulnerability tracking number, CVE-2021-29256, is a use-after-free vulnerability that allows for improper manipulation of GPU memory to allow an attacker to escalate to root level privileges and access sensitive information on the target Android device.
Arm then issued an announcement, and CTOnews.com translated it as follows:
Unprivileged users can improperly manipulate GPU memory to access freed memory and may gain root privileges and steal information.
This issue has been fixed in the Bifrost and Valhall GPU kernel driver r30p0 and in the Midgard kernel driver r31p0 version.
Google already included the flaw in its Android security update released in July.