CVE-2022-38181

HIGH KEV

Arm Mali GPU kernel driver - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-38181 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 30, 2023. EIP tracks 5 public exploits from researchers including Pro-me3us, R0rt1z2, soralis0912.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-38181, targeting the ARM Mali GPU kernel driver on Amazon FireTV 2nd gen Cube. The exploit leverages a use-after-free vulnerability to achieve arbitrary kernel code execution, disabling SELinux and gaining root access.

Description

The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.

Exploits (5)

nomisec WORKING POC 7 stars
by Pro-me3us · local
https://github.com/Pro-me3us/CVE_2022_38181_Raven

This repository contains a functional exploit for CVE-2022-38181, targeting the ARM Mali GPU kernel driver on Amazon FireTV 2nd gen Cube. The exploit leverages a use-after-free vulnerability to achieve arbitrary kernel code execution, disabling SELinux and gaining root access.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: ARM Mali GPU kernel driver (r16p0) on Amazon FireOS (32-bit userspace)
No auth needed
Prerequisites: Amazon FireTV 2nd gen Cube with vulnerable Mali driver · Local access to the device
mistral-large-3 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC 3 stars
by R0rt1z2 · local
https://github.com/R0rt1z2/CVE-2022-38181

This repository contains a functional exploit for CVE-2022-38181, targeting a vulnerability in the Mali GPU driver on Android devices. The exploit leverages memory corruption to achieve local privilege escalation (LPE) by manipulating GPU memory allocations and executing shellcode to bypass SELinux restrictions.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: Mali GPU driver (Android)
No auth needed
Prerequisites: Android device with vulnerable Mali GPU driver · Access to the device to run the exploit
mistral-large-3 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC 3 stars
by Pro-me3us · local
https://github.com/Pro-me3us/CVE_2022_38181_Gazelle

This repository contains a functional exploit for CVE-2022-38181, targeting the ARM Mali kernel driver on Amazon FireTV 3rd gen Cube. The exploit leverages a use-after-free vulnerability to achieve arbitrary kernel code execution, disable SELinux, and gain root privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: ARM Mali GPU Kernel Driver (Amazon FireTV Cube, FireOS 32-bit)
No auth needed
Prerequisites: Physical or local access to the target device · Compilation with Android NDK (ndk-21) · Execution within 30-90 seconds of device boot for reliability
mistral-large-3 · analyzed Feb 19, 2026 Full analysis →
nomisec WORKING POC
by soralis0912 · poc
https://github.com/soralis0912/CVE-2022-38181-aristotle-apk

This repository provides a functional Android APK exploit for CVE-2022-38181 (Mali GPU driver vulnerability) targeting the au/KDDI XIG04 (aristotle) device running Android 12. The exploit leverages a futex-PI use-after-free (CVE-2026-43499) to achieve temporary root and enable ADB access via a prebuilt `preload.so` payload.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: au/KDDI XIG04 (aristotle) device, Android 12, Mali GPU driver (CVE-2022-38181)
No auth needed
Prerequisites: Target device must be au/KDDI XIG04 (aristotle) running Android 12 · ARM64 architecture · Vulnerable Mali GPU driver (CVE-2022-38181) · Prebuilt exploit payload (`preload.so`) for the specific target
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →
nomisec WORKING POC
by soralis0912 · local
https://github.com/soralis0912/CVE-2022-38181-aristotle

This repository contains a functional exploit for CVE-2022-38181, a use-after-free vulnerability in the ARM Mali GPU driver (Midgard/Bifrost architectures). The exploit achieves local privilege escalation (LPE) by manipulating GPU memory management operations to corrupt kernel memory and disable SELinux, then escalate privileges to root.

Classification
Working Poc 98%
Attack Type
Lpe
Complexity
Complex
Reliability
Racy
Target: ARM Mali GPU driver (Midgard r32p1, Bifrost r32p1, specifically tested on Mali-G610 r32p1 in MediaTek MT6895/XIG04)
Auth required
Prerequisites: Local code execution in untrusted_app context (e.g., via a malicious app) · Target device with vulnerable ARM Mali GPU driver (specific kernel versions: 2108, 2201, 2202, 2207, 2211, 2212) · ARM64 architecture
mistral-large-3 · analyzed Jul 25, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.1282
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2023-03-30
VulnCheck KEV 2023-03-29
InTheWild.io 2023-03-29
ENISA EUVD EUVD-2022-40775
CWE
CWE-416
Status published
Products (5)
arm/bifrost_gpu_kernel_driver r39p0
arm/bifrost_gpu_kernel_driver r0p0 - r38p1
arm/midgard_gpu_kernel_driver r4p0 - r31p0
arm/valhall_gpu_kernel_driver r39p0
arm/valhall_gpu_kernel_driver r19p0 - r38p1
Published Oct 25, 2022
KEV Added Mar 30, 2023
Tracked Since Feb 18, 2026