CVE-2022-22706 is a critical vulnerability in Arm Mali GPU Kernel Drivers (Midgard, Bifrost, and Valhall series) that allows a non-privileged user to gain write access to read-only memory pages. With a CVSS score of 7.8 (High), this local vulnerability is easy to exploit and can lead to high impact on confidentiality, integrity, and availability. This flaw is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community and media attention. Despite its active exploitation, no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r0p0, < r36p0CPE matchmatch criteria | cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r26p0, < r32p0CPE matchmatch criteria | cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r19p0, < r36p0CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.