CVE-2022-38181
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 13% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-416
מוצרים מושפעים
arm: bifrost gpu kernel driver; arm: midgard gpu kernel driver; arm: valhall gpu kernel driver
קישורים
- https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulner… Vendor Advisory
- https://developer.arm.com/support/arm-security-updates Vendor Advisory
- https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulner… Vendor Advisory
- https://developer.arm.com/support/arm-security-updates Vendor Advisory
- https://github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-b… ExploitThird Party Advisory
- https://securitylab.github.com/advisories/GHSL-2022-054_Arm_Mali/ ExploitThird Party Advisory
- https://github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-b… ExploitThird Party Advisory
- https://securitylab.github.com/advisories/GHSL-2022-054_Arm_Mali/ ExploitThird Party Advisory
- http://packetstormsecurity.com/files/172854/Android-Arm-Mali-GPU-Arbitrary-Cod… Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/172854/Android-Arm-Mali-GPU-Arbitrary-Cod… Third Party AdvisoryVDB Entry