NA

CVE-2022-46395

Published: 06/03/2023 Updated: 13/12/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r0p0 through r32p0, Bifrost r0p0 through r41p0 before r42p0, Valhall r19p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arm avalon gpu kernel driver r41p0

arm bifrost gpu kernel driver

arm valhall gpu kernel driver

arm midgard gpu kernel driver

Github Repositories

CVE-2022-46395 POC for FireTV 2nd gen Cube (raven)

Exploit for CVE-2022-46395 to run on FireTV 2nd gen Cube This is a fork of security researcher Man Yue Mo's Pixel 6 POC for CVE-2022-46395 Read his detailed write-up of the vulnerability here Changes have been made to account for FireOS's 32-bit user space The POC exploits a bug in the ARM Mali kernel driver to gain arbitrary kernel code execution, which is then