Out-of-bounds write in ARM products - CVE-2022-22706
Published: March 30, 2023
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
The vulnerability exists due to a boundary error. A local application can trigger an out-of-bounds write and execute arbitrary code with elevated privileges. This vulnerability was patched in Google Pixel and tracked under #VU64876 (CVE-2021-39793).
Note, the vulnerability is known to be exploited in the wild in targeted attacks.
Affected software
Bifrost GPU Kernel Driver
Valhall GPU Kernel Driver
Samsung Mobile Firmware
Google Android
How to mitigate CVE-2022-22706
Bifrost GPU Kernel Driver - update to r36p0
Valhall GPU Kernel Driver - update to r36p0
Samsung Mobile Firmware - update to SMR-MAY-2023
Google Android - addressed in versions 11 2023-06-05, 12L 2023-06-05, 12 2023-06-05, 13 2023-06-05