A use-after-free vulnerability exists in the TEE (Trusted Execution Environment) subsystem of the Linux kernel, specifically in drivers/tee/tee_shm.c, affecting versions through 5.15.11. The vulnerability is due to a race condition in the tee_shm_get_from_id function, which can result in freeing a shared memory object while it is still in use.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository documents and provides resources for exploiting CVE-2021-44733, a use-after-free vulnerability in the Linux kernel TEE (Trusted Execution Environment) subsystem up to version 5.15.11. The main file, README.md, contains a detailed write-up of the vulnerability, the TEE subsystem's architecture, and the steps required to set up a test environment using OP-TEE and QEMU. It describes the process of interacting with the TEE driver via the /dev/tee0 device and various IOCTL calls, and provides a proof-of-concept (POC) exploit that demonstrates the ability to overwrite a kernel function pointer. However, the repository itself does not contain actual exploit code, but rather instructions, references, and a manifest (default.xml) for setting up the environment. The exploit is local, requiring access to a system with the vulnerable kernel and TEE subsystem enabled. No weaponized payload is included, but the environment is suitable for further research and development of privilege escalation exploits.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel use-after-free vulnerability in the Trusted Execution Environment subsystem.
Linux kernel use-after-free vulnerability in the Trusted Execution Environment subsystem.
Linux kernel use-after-free vulnerability in the Trusted Execution Environment subsystem.
Linux kernel use-after-free vulnerability in the Trusted Execution Environment subsystem.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.