Use-after-free in ARM products - CVE-2022-46891
Published: April 4, 2023
Vulnerability identifier: #VU74387
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46891
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to escalate privileges on the system.
Affected software
Midgard GPU Kernel Driver
Bifrost GPU Kernel Driver
Valhall GPU Kernel Driver
Samsung Mobile Firmware
Google Android
Bifrost GPU Kernel Driver
Valhall GPU Kernel Driver
Samsung Mobile Firmware
Google Android
How to mitigate CVE-2022-46891
Install updates from vendor's website.
Bifrost GPU Kernel Driver - update to r41p0
Valhall GPU Kernel Driver - update to r41p0
Samsung Mobile Firmware - update to SMR-JUN-2023
Google Android - addressed in versions 11 2023-05-05, 12L 2023-05-05, 12 2023-05-05, 13 2023-05-05
Valhall GPU Kernel Driver - update to r41p0
Samsung Mobile Firmware - update to SMR-JUN-2023
Google Android - addressed in versions 11 2023-05-05, 12L 2023-05-05, 12 2023-05-05, 13 2023-05-05