HIGH
CVE-2022-38181
CVSS
8.8
KEV
Description
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
Summary dbcve.org
The Arm Mali GPU kernel driver contains a use-after-free vulnerability where GPU memory operations are mishandled, allowing unprivileged users to access freed memory. This affects Bifrost (r0p0-r38p1, r39p0), Valhall (r19p0-r38p1, r39p0), and Midgard (r4p0-r32p0) GPU generations.
Mitigation
Apply Arm-provided security patches to the Mali GPU kernel driver through firmware/driver updates from the device OEM or OS vendor; prioritize systems with unprivileged user access to the GPU.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
13.56%
Probability of exploitation in next 30 days
96.3th percentile
References
http://packetstormsecurity.com/files/172854/Android-Arm-Mali-GPU-Arbitrary-Code-Execution.html
Third Party Advisory, VDB Entry
https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
Vendor Advisory
https://developer.arm.com/support/arm-security-updates
Vendor Advisory
https://github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-bug/
Exploit, Third Party Advisory
https://securitylab.github.com/advisories/GHSL-2022-054_Arm_Mali/
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-38181
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.