Arm Warns of Actively Exploited Zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-22706 | Unprivileged Memory-Write Flaw in Arm Mali GPU Kernel Drivers CVE-2022-22706 is a memory-safety flaw (CWE-119) in the Arm Mali GPU kernel driver that lets a local, non-privileged user gain write access to memory pages that should be read-only, potentially enabling privilege escalation or tampering with protected memory (CVSS 3.1: 7.8, local attack vector). It is triggered by a low-privileged local user interacting with the GPU driver on devices running affected Midgard (r26p0-r31p0), Bifrost (r0p0-r35p0), or Valhall (r19p0-r35p0) driver releases, which are widely shipped in Android SoCs such as those from MediaTek and HiSilicon. A successful attacker gains high confidentiality, integrity, and availability impact on the local device. CISA added the bug to the Known Exploited Vulnerabilities catalog on 2023-03-30, and security reporting ties Mali GPU driver zero-day exploitation to commercial spyware campaigns targeting Android and iOS users in Italy, Malaysia, Kazakhstan, and the UAE. The fix reached end users through vendor firmware, including the June 2023 Android security update. Do: Apply updated Arm Mali GPU kernel drivers via your device/SoC vendor's firmware, ensuring Android endpoints are on security patch levels that include the fix (the June 2023 Android Security Bulletin shipped the Mali driver fix). Enterprises should inventory Android devices using Mali-based SoCs (e.g., MediaTek, HiSilicon) and prioritize patching devices exposed to spyware-targeted users; no workarounds are documented, and the CISA KEV required action is to apply updates per vendor instructions. | 7.8 | 1% | KEV |
| masshundreds of millions of Android devices (Mali GPUs are integrated into a large share of Android SoCs; subset running affected driver versions) | |
| CVE-2022-38181 | Use-After-Free Vulnerability in Arm Mali GPU Kernel Driver (Bifrost/Valhall/Midgard) CVE-2022-38181 is a use-after-free (CWE-416) in the Arm Mali GPU kernel driver in which GPU memory operations are mishandled, allowing unprivileged users to access freed memory. A low-privileged attacker can trigger the flaw and gain confidentiality, integrity, and availability impact (CVSS 3.1: 8.8 High), typically leveraged within exploit chains to escalate privileges in the kernel. The bug affects the Bifrost, Valhall, and Midgard Mali driver families across the version ranges listed below, meaning virtually any device running an affected Mali GPU driver is exposed, including Android smartphones such as Google Pixel devices. The vulnerability is being actively exploited: it was used in commercial spyware campaigns on Android and iOS devices reported in Italy, Malaysia, Kazakhstan, and the UAE, documented by Google TAG and GitHub Security Lab, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-03-30. Do: Apply updates per vendor instructions as required by CISA KEV: device makers and SoC integrators should upgrade the Mali GPU kernel driver to releases newer than the affected ranges (beyond r39p0 for Bifrost/Valhall and beyond r32p0 for Midgard). End users and administrators should promptly install the latest Android/security firmware updates from their device vendor and inventory devices running affected Mali drivers for prioritized patching. | 8.8 | 14% | KEV PoC ×2 |
| masshundreds of millions to billions of devices (Mali GPUs ship in a large share of Android smartphones and embedded Arm systems) | |
| CVE-2023-4211 | Use-After-Free in Arm Mali GPU Kernel Driver (Actively Exploited) CVE-2023-4211 is a use-after-free (CWE-416) in Arm's Mali GPU kernel drivers, covering the Midgard, Bifrost, Valhall and 5th Gen GPU Architecture product lines. A local, non-privileged attacker triggers the flaw by issuing improper GPU memory processing operations, causing the driver to access memory that has already been freed. Successful exploitation exposes already-freed kernel memory to the attacker (high confidentiality impact per the CVSS score), which on mobile devices can be chained into broader local information-gathering or privilege attacks. Any system running the affected Mali kernel drivers is exposed — in practice this is overwhelmingly Android smartphones, tablets and embedded devices whose SoCs integrate Mali GPUs. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-03, indicating confirmed in-the-wild exploitation; Arm has issued updated drivers, but patch availability varies by device vendor. Do: Determine whether devices in your fleet use Mali GPUs and obtain updated Mali GPU kernel drivers from Arm via your device vendor's security updates (OEM/Android updates issued from October 2023 onward), since Arm fixes are distributed through device vendors rather than a standalone Arm patch channel. Until devices are patched, limit local, unprivileged access on affected systems to trusted users and monitor vendor bulletins for availability. Per the CISA KEV required action, apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | 5.5 | 1% | KEV |
| mass≈1 billion+ devices (Mali GPUs are integrated in a very large share of Android smartphones, tablets and embedded devices) | |
| CVE-2024-4610 | Use-After-Free in Arm Mali Bifrost/Valhall GPU Kernel Drivers Exploited in the Wild CVE-2024-4610 is a use-after-free (CWE-416) in Arm's Bifrost and Valhall Mali GPU kernel drivers, affecting driver builds from r34p0 through r40p0. A local, non-privileged user can trigger improper GPU memory processing operations that cause the driver to access already-freed memory. A successful exploit can yield high-impact outcomes — confidentiality, integrity and availability are all rated high, implying kernel-level information disclosure or code execution in the context of the GPU driver — and it could also be chained with other bugs in remote exploitation chains. Any device shipping a Mali Bifrost/Valhall driver in the affected range is exposed, including Android smartphones and other SoC-based products from vendors that integrate Mali GPUs. The flaw is being actively exploited in the wild: Arm warned of in-the-wild zero-day use, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-06-12, and related reporting ties it to spyware-grade exploitation (Intellexa/Predator and a Google warning about a Pixel firmware zero-day). Do: Update to a fixed Arm Mali Bifrost/Valhall GPU kernel driver release newer than r40p0, which for most users means applying the latest Android/SoC/device vendor firmware updates (e.g., Google's updated Pixel firmware). Organizations managing fleets should inventory devices built on affected Mali driver versions (Pixel, MediaTek Dimensity, Exynos handsets; Rockchip/Amlogic boards) and prioritize them for patching given confirmed in-the-wild exploitation. Federal agencies must apply vendor mitigations per CISA KEV requirements within the mandated deadline, and defenders should treat local or chained remote exploitation paths as realistic, consistent with the spyware-usage reporting. | 7.8 | <1% | KEV |
| mass≈hundreds of millions of Android devices and SoC-based systems with Mali Bifrost/Valhall GPUs in the affected driver range |
Full article334 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 11, 2024Mobile Security / Technology
Arm is warning of a security vulnerability impacting Mali GPU Kernel Driver that it said has been actively exploited in the wild.
Tracked as CVE-2024-4610, the use-after-free issue impacts the following products -
- Bifrost GPU Kernel Driver (all versions from r34p0 to r40p0)
- Valhall GPU Kernel Driver (all versions from r34p0 to r40p0)
"A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory," the company said in an advisory last week.
The vulnerability has been addressed in Bifrost and Valhall GPU Kernel Driver r41p0. It's worth noting that this version was released on November 24, 2022. The current version of the drivers is r49p0, which was shipped in April 2024.
When reached for comment, Arm told The Hacker News that while it was addressed in 2022, it was provided additional information that reclassified the problem as a security vulnerability.
"In 2022 Arm fixed a weakness in the r41p0 release for the Bifrost and Valhall Mali GPU kernel driver," a spokesperson for the company said. "An external researcher recently provided new information which reclassifies this weakness as a vulnerability. After Arm assessed this issue as a vulnerability, a CVE was published."
The British semiconductor company further acknowledged reports of the shortcoming being exploited in real-world attacks, but did not disclose any additional specifics to prevent further abuse.
That said, previously disclosed zero-day flaws in Arm Mali GPU – CVE-2022-22706, CVE-2022-38181 and CVE-2023-4211 – have been weaponized by commercial spyware vendors for highly targeted attacks aimed at Android devices, with the exploitation of the latter linked to an Italian company named Cy4Gate.
Users of affected products are recommended to update to the appropriate version to secure against potential threats.
(The story was updated after publication on June 17, 2024, to include a response from Arm.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/06/arm-warns-of-actively-exploited-zero.html