ZeroHour

CVE-2022-22706

KEVmass

Unprivileged Memory-Write Flaw in Arm Mali GPU Kernel Drivers

CISA: Arm Mali GPU Kernel Driver Unspecified Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p64
Published
()
KEV added
AI analysis

CVE-2022-22706 is a memory-safety flaw (CWE-119) in the Arm Mali GPU kernel driver that lets a local, non-privileged user gain write access to memory pages that should be read-only, potentially enabling privilege escalation or tampering with protected memory (CVSS 3.1: 7.8, local attack vector). It is triggered by a low-privileged local user interacting with the GPU driver on devices running affected Midgard (r26p0-r31p0), Bifrost (r0p0-r35p0), or Valhall (r19p0-r35p0) driver releases, which are widely shipped in Android SoCs such as those from MediaTek and HiSilicon. A successful attacker gains high confidentiality, integrity, and availability impact on the local device. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2023-03-30, and security reporting ties Mali GPU driver zero-day exploitation to commercial spyware campaigns targeting Android and iOS users in Italy, Malaysia, Kazakhstan, and the UAE. The fix reached end users through vendor firmware, including the June 2023 Android security update.

What to do: Apply updated Arm Mali GPU kernel drivers via your device/SoC vendor's firmware, ensuring Android endpoints are on security patch levels that include the fix (the June 2023 Android Security Bulletin shipped the Mali driver fix). Enterprises should inventory Android devices using Mali-based SoCs (e.g., MediaTek, HiSilicon) and prioritize patching devices exposed to spyware-targeted users; no workarounds are documented, and the CISA KEV required action is to apply updates per vendor instructions.

Affected
Arm Midgard GPU kernel driverr26p0 through r31p0
Arm Bifrost GPU kernel driverr0p0 through r35p0
Arm Valhall GPU kernel driverr19p0 through r35p0
Estimated exposure
masshundreds of millions of Android devices (Mali GPUs are integrated into a large share of Android SoCs; subset running affected driver versions) — Mali GPUs ship in SoCs from MediaTek, HiSilicon and other vendors used across hundreds of millions of Android handsets and tablets, so the affected driver-version subset still plausibly covers hundreds of millions of devices, though the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.

CISA Known Exploited Vulnerability
Affected
Arm Mali Graphics Processing Unit (GPU)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
arm
Products
bifrost gpu kernel driver, midgard gpu kernel driver, valhall gpu kernel driver
Weakness
CWE-119
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news