Vulnerability record · CVE-2022-22706 · published 3 March 2022
CVE-2022-22706: Arm Mali GPU Kernel Driver read-only memory write flaw
Arm · Bifrost Gpu Kernel Driver
The Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting Midgard r26p0-r31p0, Bifrost r0p0-r35p0 and Valhall r19p0-r35p0. Because it breaks the read-only memory boundary from an unprivileged context, it is a serious local privilege-escalation primitive on affected devices.
Description
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityConfirmed in-the-wild exploitation via CISA KEV and a high-severity local privilege-escalation primitive, though EPSS probability is low and exploitation requires local access.
What it is
The Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting Midgard r26p0-r31p0, Bifrost r0p0-r35p0 and Valhall r19p0-r35p0. Because it breaks the read-only memory boundary from an unprivileged context, it is a serious local privilege-escalation primitive on affected devices.
Impact
An attacker with local unprivileged code execution can corrupt read-only kernel memory, enabling privilege escalation and full compromise of confidentiality, integrity and availability on the device.
Attack surface
Reached locally by a non-privileged user through the Mali GPU kernel driver; the CVSS vector AV:L/PR:L/UI:N indicates low privileges are required and no user interaction is needed. No remote or network vector is described.
Exploitation
CVE-2022-22706 is listed in CISA KEV (added 2023-03-30), confirming exploitation in the wild; EPSS 30-day probability is low at roughly 1.1 percent (63rd percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor updates listed in Arm's Mali GPU kernel driver security advisory.
- Track affected Midgard, Bifrost and Valhall driver versions and confirm each device is on a fixed release.
- Restrict local code execution and untrusted app installation on devices that cannot be patched promptly.
- Monitor Arm security updates for further revisions covering these driver branches.
Detection
- Audit device and driver inventory for Mali Midgard, Bifrost and Valhall kernel drivers in the affected version ranges.
- Monitor for unexpected writes or faults against read-only kernel memory pages on Mali-based devices.
- Alert on local privilege-escalation behavior from unprivileged processes interacting with the GPU driver.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22706 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Arm Mali GPU Kernel Driver Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://developer.arm.com/support/arm-security-updates | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates | Vendor Advisory |
| https://developer.arm.com/support/arm-security-updates/mali-gpu-kernel-driver | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22706 | US Government Resource |
Track CVE-2022-22706 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22706), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.