PT-2022-26516 · Arm · Arm Mali Gpu Kernel Driver

Published

2022-12-12

·

Updated

2024-10-15

·

CVE-2022-42716

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Arm Mali GPU Kernel Driver versions Midgard r4p0 through r32p0 Arm Mali GPU Kernel Driver versions Bifrost r1p0 through r40p0 Arm Mali GPU Kernel Driver versions Valhall r19p0 through r40p0
Description A use-after-free issue was discovered in the Arm Mali GPU Kernel Driver, allowing a non-privileged user to make improper GPU processing operations to gain access to already freed memory.
Recommendations For versions Midgard r4p0 through r32p0, consider disabling the GPU processing operations until a patch is available. For versions Bifrost r1p0 through r40p0, restrict access to the GPU kernel driver to minimize the risk of exploitation. For versions Valhall r19p0 through r40p0, avoid using the GPU for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ASB-A-260148146
CVE-2022-42716

Affected Products

Arm Mali Gpu Kernel Driver