← Vulnerability feed

Vulnerability record · CVE-2022-22706 · published 3 March 2022

CVE-2022-22706: Arm Mali GPU Kernel Driver read-only memory write flaw

Arm · Bifrost Gpu Kernel Driver

The Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting Midgard r26p0-r31p0, Bifrost r0p0-r35p0 and Valhall r19p0-r35p0. Because it breaks the read-only memory boundary from an unprivileged context, it is a serious local privilege-escalation primitive on affected devices.

7.8 CVSS 3.1 High CISA KEV since 30 Mar 2023 EPSS 1.1% · top 36.8% CWE-119 · Memory buffer overflow
7.8CVSS 3.1 base score, v2 4.6
1.1%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityConfirmed in-the-wild exploitation via CISA KEV and a high-severity local privilege-escalation primitive, though EPSS probability is low and exploitation requires local access.

What it is

The Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting Midgard r26p0-r31p0, Bifrost r0p0-r35p0 and Valhall r19p0-r35p0. Because it breaks the read-only memory boundary from an unprivileged context, it is a serious local privilege-escalation primitive on affected devices.

Impact

An attacker with local unprivileged code execution can corrupt read-only kernel memory, enabling privilege escalation and full compromise of confidentiality, integrity and availability on the device.

Attack surface

Reached locally by a non-privileged user through the Mali GPU kernel driver; the CVSS vector AV:L/PR:L/UI:N indicates low privileges are required and no user interaction is needed. No remote or network vector is described.

Exploitation

CVE-2022-22706 is listed in CISA KEV (added 2023-03-30), confirming exploitation in the wild; EPSS 30-day probability is low at roughly 1.1 percent (63rd percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor updates listed in Arm's Mali GPU kernel driver security advisory.
  • Track affected Midgard, Bifrost and Valhall driver versions and confirm each device is on a fixed release.
  • Restrict local code execution and untrusted app installation on devices that cannot be patched promptly.
  • Monitor Arm security updates for further revisions covering these driver branches.

Detection

  • Audit device and driver inventory for Mali Midgard, Bifrost and Valhall kernel drivers in the affected version ranges.
  • Monitor for unexpected writes or faults against read-only kernel memory pages on Mali-based devices.
  • Alert on local privilege-escalation behavior from unprivileged processes interacting with the GPU driver.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22706 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Arm Mali GPU Kernel Driver Unspecified Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22706 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2022-38181Arm Mali GPU kernel driver use-after-free via mishandled GPU memory operationsThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affe…KEVEPSS 14%analysed8.8CVE-2021-29256Arm Mali GPU kernel driver use-after-free allows privilege escalationThe Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitat…KEVEPSS 3.0%analysed8.8CVE-2021-28663Arm Mali GPU kernel driver use-after-free privilege escalationThe Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker…KEVEPSS 12%analysed8.8CVE-2021-28664Arm Mali GPU kernel driver out-of-bounds write allows privilege escalationThe Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privi…KEVEPSS 5.4%analysed7.8CVE-2024-4610Arm Mali GPU kernel driver use-after-free lets local user access freed memoryThe Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU me…KEVEPSS 0.76%analysed5.5CVE-2023-4211Arm Mali GPU Kernel Driver use-after-free via improper GPU memory handlingThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A l…KEVEPSS 1.1%analysed3.3CVE-2023-26083Arm Mali GPU Kernel Driver memory leak exposes kernel metadataThe Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0…KEVEPSS 1.2%analysed9.8CVE-2022-28349Arm bifrost gpu kernel driver use after free vulnerabilityArm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2022-22706), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.