CVE-2022-28348
Last modified
CVE-2022-28348 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.. EPSS estimates a 1.27% chance of exploitation in the next 30 days.
Description
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p0) allows improper GPU memory operations to reach a use-after-free situation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arm | Bifrost Gpu Kernel Driver | >= r0p0, <= r36p0 |
| Arm | Midgard Gpu Kernel Driver | >= r4p0, <= r31p0 |
| Arm | Valhall Gpu Kernel Driver | >= r19p0, <= r36p0 |
References
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
- https://developer.arm.com/support/arm-security-updatesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-28348?
How severe is CVE-2022-28348?
How do I fix CVE-2022-28348?
Are you affected by CVE-2022-28348?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
