Use-after-free in ARM products - CVE-2022-38181
Published: March 30, 2023 / Updated: January 15, 2024
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a use-after-free error. A local application can trigger memory corruption and execute arbitrary code with elevated privileges.
Note, this vulnerability is known to be exploited in targeted attacks spotted in November 2022.
Affected software
Bifrost GPU Kernel Driver
Valhall GPU Kernel Driver
Google Android
Samsung Mobile Firmware
How to mitigate CVE-2022-38181
Valhall GPU Kernel Driver - addressed in versions r38p2, r40p0
Google Android - addressed in versions 11 2023-04-05, 12L 2023-04-05, 12 2023-04-05, 13 2023-04-05
Samsung Mobile Firmware - update to SMR-MAY-2023
Links to Public Exploits and PoC-codes
External References
- https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities
- https://github.blog/2023-01-23-pwning-the-all-google-phone-with-a-non-google-bug/
- https://securitylab.github.com/advisories/GHSL-2022-054_Arm_Mali/
- https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/