CVE-2022-38181 is a use-after-free vulnerability in the Arm Mali GPU kernel driver, affecting Bifrost, Valhall, and Midgard GPU versions. This critical flaw allows unprivileged users to access freed memory due to mishandled GPU memory operations. With a CVSS score of 8.8 (HIGH), it presents a significant risk, allowing for high impact to confidentiality, integrity, and availability with low attack complexity and no user interaction required. This vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered substantial community discussion and media coverage, despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r0p0, <= r38p1CPE matchmatch criteria | cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
r39p0CPE matchmatch criteria | cpe:2.3:a:arm:bifrost_gpu_kernel_driver:r39p0:*:*:*:*:*:*:* | ||
>= r4p0, <= r31p0CPE matchmatch criteria | cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r19p0, <= r38p1CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
r39p0CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:r39p0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.