Out-of-bounds write in ARM products - CVE-2022-22706

 

Out-of-bounds write in ARM products - CVE-2022-22706

Published: March 30, 2023


Vulnerability identifier: #VU74192
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22706
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error. A local application can trigger an out-of-bounds write and execute arbitrary code with elevated privileges. This vulnerability was patched in Google Pixel and tracked under #VU64876 (CVE-2021-39793).

Note, the vulnerability is known to be exploited in the wild in targeted attacks.


Affected software

Midgard GPU Kernel Driver
Bifrost GPU Kernel Driver
Valhall GPU Kernel Driver
Samsung Mobile Firmware
Google Android

How to mitigate CVE-2022-22706

Install updates from vendor's website.

Midgard GPU Kernel Driver - update to r32p0
Bifrost GPU Kernel Driver - update to r36p0
Valhall GPU Kernel Driver - update to r36p0
Samsung Mobile Firmware - update to SMR-MAY-2023
Google Android - addressed in versions 11 2023-06-05, 12L 2023-06-05, 12 2023-06-05, 13 2023-06-05

External References

Related Security Bulletins