CVE-2022-28348
published 2022-05-19CVE-2022-28348: Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper…
PriorityP343critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.27%
66.2th percentile
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| arm | bifrost_gpu_kernel_driver | r0p0 – r36p0 | — |
| arm | midgard_gpu_kernel_driver | r4p0 – r31p0 | — |
| arm | valhall_gpu_kernel_driver | r19p0 – r36p0 | — |
| android | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r85c-7543-8wq6: Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows
ghsa_unreviewed·2022-05-20
CVE-2022-28348 [CRITICAL] CWE-416 GHSA-r85c-7543-8wq6: Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.
Android
CVE-2022-28348: Mali
vendor_android·2023-10-01·CVSS 9.8
CVE-2022-28348 [CRITICAL] CVE-2022-28348: Mali
Android Security Bulletin 2023-10-01
CVE: CVE-2022-28348
Severity: HIGH
Component: Mali
References: A-296463357
*
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-19
Published