The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
References
Configurations
Configuration 1 (hide)
|
History
03 Nov 2025, 15:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-38181 - US Government Resource |
22 Oct 2025, 00:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 20:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Oct 2025, 19:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://packetstormsecurity.com/files/172854/Android-Arm-Mali-GPU-Arbitrary-Code-Execution.html - Third Party Advisory, VDB Entry | |
| References | () https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - Vendor Advisory | |
| References | () https://developer.arm.com/support/arm-security-updates - Vendor Advisory | |
| References | () https://github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-bug/ - Exploit, Third Party Advisory | |
| References | () https://securitylab.github.com/advisories/GHSL-2022-054_Arm_Mali/ - Exploit, Third Party Advisory |
28 Jun 2024, 13:41
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://packetstormsecurity.com/files/172854/Android-Arm-Mali-GPU-Arbitrary-Code-Execution.html - Third Party Advisory, VDB Entry |
13 Dec 2023, 13:51
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:arm:midgard_gpu_kernel_driver:*:*:*:*:*:*:*:* |
12 Jun 2023, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Mar 2023, 18:11
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Summary | The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0. |
28 Oct 2022, 19:00
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://developer.arm.com/support/arm-security-updates - Vendor Advisory | |
| References | (MISC) https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CPE | cpe:2.3:a:arm:valhall_gpu_kernel_driver:r39p0:*:*:*:*:*:*:* cpe:2.3:a:arm:bifrost_gpu_kernel_driver:r39p0:*:*:*:*:*:*:* cpe:2.3:a:arm:bifrost_gpu_kernel_driver:*:*:*:*:*:*:*:* cpe:2.3:a:arm:midguard_gpu_kernel_driver:*:*:*:*:*:*:*:* cpe:2.3:a:arm:valhall_gpu_kernel_driver:*:*:*:*:*:*:*:* |
|
| CWE | CWE-416 |
25 Oct 2022, 19:36
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2022-10-25 19:15
Updated : 2025-11-03 15:43
NVD link : CVE-2022-38181
Mitre link : CVE-2022-38181
CVE.ORG link : CVE-2022-38181
JSON object : View
Products Affected
arm
- midgard_gpu_kernel_driver
- bifrost_gpu_kernel_driver
- valhall_gpu_kernel_driver
CWE
CWE-416
Use After Free
