CVE-2022-38181
arm bifrost gpu kernel driver, arm midgard gpu kernel driver, arm valhall gpu kernel driver
Published 25 Oct 2022 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 30 Mar 2023, with a remediation deadline of 20 Apr 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
References
- packetstormsecurity.com/files/172854/Android-Arm-Mali-GPU-Arbitrary-Code-Execution.html · Third Party Advisory, VDB Entry
- developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities · Vendor Advisory
- developer.arm.com/support/arm-security-updates · Vendor Advisory
- github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-bug/ · Exploit, Third Party Advisory
- securitylab.github.com/advisories/GHSL-2022-054_Arm_Mali/ · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-38181 · US Government Resource