// For flags

CVE-2022-38181

Arm Mali GPU Kernel Driver Use-After-Free Vulnerability

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.

Un controlador del kernel de la GPU del correo de la familia de productos Arm versiones hasta 12-08-2022, permite a usuarios no privilegiados realizar operaciones de procesamiento de la GPU inapropiadas para conseguir acceso a la memoria ya liberada

Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-08-12 CVE Reserved
  • 2022-10-25 CVE Published
  • 2023-03-30 Exploited in Wild
  • 2023-04-20 KEV Due Date
  • 2024-08-03 CVE Updated
  • 2024-08-03 First Exploit
  • 2024-11-20 EPSS Updated
CWE
  • CWE-416: Use After Free
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Arm
Search vendor "Arm"
Bifrost Gpu Kernel Driver
Search vendor "Arm" for product "Bifrost Gpu Kernel Driver"
>= r0p0 <= r38p1
Search vendor "Arm" for product "Bifrost Gpu Kernel Driver" and version " >= r0p0 <= r38p1"
-
Affected
Arm
Search vendor "Arm"
Bifrost Gpu Kernel Driver
Search vendor "Arm" for product "Bifrost Gpu Kernel Driver"
r39p0
Search vendor "Arm" for product "Bifrost Gpu Kernel Driver" and version "r39p0"
-
Affected
Arm
Search vendor "Arm"
Midgard Gpu Kernel Driver
Search vendor "Arm" for product "Midgard Gpu Kernel Driver"
>= r4p0 <= r31p0
Search vendor "Arm" for product "Midgard Gpu Kernel Driver" and version " >= r4p0 <= r31p0"
-
Affected
Arm
Search vendor "Arm"
Valhall Gpu Kernel Driver
Search vendor "Arm" for product "Valhall Gpu Kernel Driver"
>= r19p0 <= r38p1
Search vendor "Arm" for product "Valhall Gpu Kernel Driver" and version " >= r19p0 <= r38p1"
-
Affected
Arm
Search vendor "Arm"
Valhall Gpu Kernel Driver
Search vendor "Arm" for product "Valhall Gpu Kernel Driver"
r39p0
Search vendor "Arm" for product "Valhall Gpu Kernel Driver" and version "r39p0"
-
Affected