CVE-2022-38181
KEVHIGH 8.8EPSS 13.6%
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 13.56% chance of exploitation in the next 30 days, 96th percentile
- CISA KEV
- added 2023-03-30
- Published
- 2022-10-25
- Updated
- 2025-10-21
Proof-of-concept exploits (7)
- https://github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-bug/
- Bariskizilkaya/CVE_2022_38181-Mali-SAMSUNG-S6-Lite-Tablet0★ · 2025-03-20
- Pro-me3us/CVE_2022_38181_Gazelle4★ · 2023-06-29
- Pro-me3us/CVE_2022_38181_Raven7★ · 2024-12-03
- R0rt1z2/CVE-2022-381813★ · 2023-07-03
- soralis0912/CVE-2022-38181-aristotle
- hackintoanetwork/SCRoot