CVE-2022-46891 is a high-severity use-after-free vulnerability in Arm Mali GPU Kernel Drivers (Midgard, Bifrost, and Valhall series). A non-privileged user can exploit this by crafting improper GPU processing operations to access freed memory, potentially leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 8.8, it presents a significant risk, though no public exploit code or active exploitation has been observed, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= r1p0, <= r40p0CPE matchmatch criteria | cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r13p0, <= r32p0CPE matchmatch criteria | cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:* | ||
>= r19p0, <= r40p0CPE matchmatch criteria | cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.