CVE-2022-38181highunder attackCWE-416

CVE-2022-38181

Published · Updated

76Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 8.8epss 14%
from disclosure to weapon170 days
Published on NVDOct 25
1st PoC+170d
CISA KEV+156d
exploitation probability
14%top 4% of all CVEs
observed exploitation
yesCISA + VulnCheck
10 public exploit(s)
Action required by CISAfederal deadline: 2023-04-20

Apply updates per vendor instructions.

In short

The Arm Mali GPU driver has a flaw that lets unprivileged users access memory that has already been freed, potentially causing crashes or system compromise. This happens because the driver doesn't properly manage GPU memory operations.

Technical detail

Use-after-free vulnerability in Arm Mali GPU kernel driver affecting Bifrost, Valhall, and Midgard architectures. Unprivileged local users can trigger freed memory access through GPU operations without proper state validation, leading to information disclosure or denial of service.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.