CVE-2022-38181

EUVD-2022-40775
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
armbifrost_gpu_kernel_driver
r0p0 ≤
𝑥
≤ r38p1
armmidgard_gpu_kernel_driver
r4p0 ≤
𝑥
≤ r31p0
armvalhall_gpu_kernel_driver
r19p0 ≤
𝑥
≤ r38p1
𝑥
= Vulnerable software versions