Arm

Arm

Top 10K site
Bounty USD $500 - $20,000

Program Details

Handle
arm
Confidentiality
public

Scope (4 targets)

other: 4

In Scope

  • TrustedFirmware-A (TF-A) other bounty-eligible
  • TrustedFirmware-M (TF-M) other bounty-eligible
  • TF-PSA-Crypto other bounty-eligible
  • OP-TEE other bounty-eligible

Known Exploited Vulnerabilities 9CVEs

  • CVE-2024-4610Mali GPU Kernel DriverJun 12, 20240.8% EPSS

    Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

  • CVE-2023-4211Mali GPU Kernel DriverOct 3, 20231.1% EPSS

    Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.

  • CVE-2021-29256Mali Graphics Processing Unit (GPU)Jul 7, 20233.0% EPSS

    Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

  • CVE-2023-26083Mali Graphics Processing Unit (GPU)Apr 7, 20231.2% EPSS

    Arm Mali GPU Kernel Driver contains an information disclosure vulnerability that allows a non-privileged user to make valid GPU processing operations that expose sensitive kernel metadata.

  • CVE-2022-38181Mali Graphics Processing Unit (GPU)Mar 30, 202313.6% EPSS

    Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

  • CVE-2022-22706Mali Graphics Processing Unit (GPU)Mar 30, 20231.1% EPSS

    Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.

  • CVE-2021-27562Trusted FirmwareNov 3, 20213.1% EPSS

    Arm Trusted Firmware contains an out-of-bounds write vulnerability allowing the non-secure (NS) world to trigger a system halt, overwrite secure data, or print out secure data when calling secure functions under the non-secure processing environment (NSPE) handler mode. This vulnerability affects Yealink Device Management servers.

  • CVE-2021-28664Mali Graphics Processing Unit (GPU)Nov 3, 20215.4% EPSS

    Arm Mali Graphics Processing Unit (GPU) kernel driver contains an unspecified vulnerability that may allow a non-privileged user to gain write access to read-only memory, gain root privilege, corrupt memory, and modify the memory of other processes.

  • CVE-2021-28663Mali Graphics Processing Unit (GPU)Nov 3, 202112.1% EPSS

    Arm Mali Graphics Processing Unit (GPU) kernel driver contains a use-after-free vulnerability that may allow a non-privileged user to make improper operations on GPU memory to gain root privilege, and/or disclose information.

security.txt

Contact
https://support.arm.com/arm-product-security-center
Expires
Aug 6, 2027
View raw security.txt →