Out-of-bounds read in ARM Avalon GPU Kernel Driver and Valhall GPU Kernel Driver - CVE-2022-46396
Published: April 4, 2023
Vulnerability identifier: #VU74393
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-46396
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition. A local application can trigger an out-of-bounds read error and read contents of memory on the system.
Affected software
ARM Avalon GPU Kernel Driver
Valhall GPU Kernel Driver
Samsung Mobile Firmware
Google Android
Valhall GPU Kernel Driver
Samsung Mobile Firmware
Google Android
How to mitigate CVE-2022-46396
Install updates from vendor's website.
ARM Avalon GPU Kernel Driver - update to r42p0
Valhall GPU Kernel Driver - update to r42p0
Samsung Mobile Firmware - update to SMR-JUN-2023
Google Android - addressed in versions 11 2023-05-05, 12L 2023-05-05, 12 2023-05-05, 13 2023-05-05
Valhall GPU Kernel Driver - update to r42p0
Samsung Mobile Firmware - update to SMR-JUN-2023
Google Android - addressed in versions 11 2023-05-05, 12L 2023-05-05, 12 2023-05-05, 13 2023-05-05