← Vulnerability feed

Vulnerability record · CVE-2022-38181 · published 25 October 2022

CVE-2022-38181: Arm Mali GPU kernel driver use-after-free via mishandled GPU memory operations

Arm · Bifrost Gpu Kernel Driver

The Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affects Bifrost r0p0 through r38p1 and r39p0, Valhall r19p0 through r38p1 and r39p0, and Midgard r4p0 through r32p0. Because the flaw is reachable by unprivileged local users and yields high confidentiality, integrity and availability impact, it is a serious privilege-escalation and sandbox-escape primitive on affected devices.

8.8 CVSS 3.1 High CISA KEV since 30 Mar 2023 EPSS 14% · top 3.7% CWE-416 · Use after free
8.8CVSS 3.1 base score
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
11References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with public exploit references and high CVSS impact, but exploitation requires local low-privileged access rather than being remotely reachable without prerequisites.

What it is

The Arm Mali GPU kernel driver mishandles GPU memory operations, allowing unprivileged users to access freed memory (CWE-416 use-after-free). It affects Bifrost r0p0 through r38p1 and r39p0, Valhall r19p0 through r38p1 and r39p0, and Midgard r4p0 through r32p0. Because the flaw is reachable by unprivileged local users and yields high confidentiality, integrity and availability impact, it is a serious privilege-escalation and sandbox-escape primitive on affected devices.

Impact

An attacker gains access to freed GPU memory, which can lead to memory corruption and arbitrary code execution in the kernel context. Public references describe Android arbitrary code execution, so the practical gain is kernel-level code execution and potential full device compromise.

Attack surface

The CVSS vector is network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), but the description states the driver allows unprivileged users to access freed memory, indicating a local attack surface on the device. Reaching the flaw requires the ability to issue GPU memory operations, i.e. code already running on the target with low privileges; no user interaction is needed.

Exploitation

CVE-2022-38181 is listed in CISA KEV (added 2023-03-30, due 2023-04-20) and has an EPSS 30-day probability of 0.13556 (96.3rd percentile). Multiple references are tagged Exploit, including GitHub Security Lab and GitHub blog write-ups, so public exploit material exists; KEV records no known ransomware campaign use.

What to do

  • Apply the vendor updates listed in Arm's Mali GPU Driver Vulnerabilities and Arm Security Updates advisories for the affected Bifrost, Valhall and Midgard driver versions.
  • For Android devices, install the OEM/Google security patch level that includes the Mali driver fix; verify the patch level rather than assuming it.
  • Where patching is not immediately possible, restrict or remove untrusted applications that can issue GPU memory operations, and reduce the number of low-privileged local users on affected devices.
  • Track affected device fleets by GPU driver version (Bifrost, Valhall, Midgard) and prioritize internet-exposed or multi-tenant devices.
  • Monitor vendor advisories for updated fixed driver revisions, since the affected range spans many rXpY releases.

Detection

  • Inventory devices and firmware reporting Mali Bifrost, Valhall or Midgard GPU kernel driver versions in the affected ranges.
  • Monitor for kernel crashes, GPU driver faults and use-after-free style memory corruption reports in device logs on affected hardware.
  • Hunt for unexpected privilege escalation or code execution originating from processes interacting with the GPU driver, especially on Android devices.
  • Correlate endpoint telemetry with known exploit artifacts from the public GitHub Security Lab and GitHub blog write-ups for this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-38181 to the Known Exploited Vulnerabilities catalog on 30 March 2023 as "Arm Mali GPU Kernel Driver Use-After-Free Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 20 April 2023.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-38181 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-29256Arm Mali GPU kernel driver use-after-free allows privilege escalationThe Arm Mali GPU kernel driver contains a use-after-free (CWE-416) that an unprivileged user can trigger to access freed memory. Successful exploitat…KEVEPSS 3.0%analysed8.8CVE-2021-28663Arm Mali GPU kernel driver use-after-free privilege escalationThe Arm Mali GPU kernel driver mishandles GPU memory operations, producing a use-after-free in Bifrost, Valhall and Midgard drivers. A local attacker…KEVEPSS 12%analysed8.8CVE-2021-28664Arm Mali GPU kernel driver out-of-bounds write allows privilege escalationThe Arm Mali GPU kernel driver lets an unprivileged user gain read/write access to read-only pages, causing memory corruption. This can lead to privi…KEVEPSS 5.4%analysed7.8CVE-2024-4610Arm Mali GPU kernel driver use-after-free lets local user access freed memoryThe Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free (CWE-416) reachable by a local non-privileged user performing improper GPU me…KEVEPSS 0.76%analysed7.8CVE-2022-22706Arm Mali GPU Kernel Driver read-only memory write flawThe Arm Mali GPU kernel driver lets a non-privileged user gain write access to read-only memory pages, a memory buffer overflow (CWE-119) affecting M…KEVEPSS 1.1%analysed5.5CVE-2023-4211Arm Mali GPU Kernel Driver use-after-free via improper GPU memory handlingThe Arm Mali GPU kernel driver mishandles GPU memory operations, allowing a use-after-free (CWE-416) in which freed memory can be accessed again. A l…KEVEPSS 1.1%analysed3.3CVE-2023-26083Arm Mali GPU Kernel Driver memory leak exposes kernel metadataThe Arm Mali GPU kernel driver has a memory leak (CWE-401) across Midgard r6p0-r32p0, Bifrost r0p0-r42p0, Valhall r19p0-r42p0, and Avalon r41p0-r42p0…KEVEPSS 1.2%analysed9.8CVE-2022-28349Arm bifrost gpu kernel driver use after free vulnerabilityArm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valhall r19p…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2022-38181), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.