CVE-2022-38181

HIGH KEV

Arm Mali GPU kernel driver - Memory Corruption

Title source: llm

Description

The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.

Exploits (3)

nomisec WORKING POC 7 stars
by Pro-me3us · local
https://github.com/Pro-me3us/CVE_2022_38181_Raven
nomisec WORKING POC 3 stars
by R0rt1z2 · local
https://github.com/R0rt1z2/CVE-2022-38181
nomisec WORKING POC 3 stars
by Pro-me3us · local
https://github.com/Pro-me3us/CVE_2022_38181_Gazelle

Scores

CVSS v3 8.8
EPSS 0.2455
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2023-03-30
VulnCheck KEV 2023-03-29
InTheWild.io 2023-03-29
ENISA EUVD EUVD-2022-40775
CWE
CWE-416
Status published
Products (5)
arm/bifrost_gpu_kernel_driver r39p0
arm/bifrost_gpu_kernel_driver r0p0 - r38p1
arm/midgard_gpu_kernel_driver r4p0 - r31p0
arm/valhall_gpu_kernel_driver r39p0
arm/valhall_gpu_kernel_driver r19p0 - r38p1
Published Oct 25, 2022
KEV Added Mar 30, 2023
Tracked Since Feb 18, 2026