CVE-2022-36449: Use After Free
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory, write a limited amount outside of buffer bounds, or to disclose details of memory mappings. This affects Midgard r4p0 through r32p0, Bifrost r0p0 through r38p0 and r39p0 before r38p1, and Valhall r19p0 through r38p0 and r39p0 before r38p1.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36449?
CVE-2022-36449 is a vulnerability discovered in the Arm Mali GPU Kernel Driver that allows a non-privileged user to gain access to already freed memory, write outside of buffer bounds, or disclose memory mappings.
How does CVE-2022-36449 affect Arm Mali GPU systems?
CVE-2022-36449 affects Arm Mali GPU systems from Midgard r4p0 through r32p0, as well as Bifrost r0p0 through r38p0 and Valhall r19p0 through r38p0.
What is the severity of CVE-2022-36449?
The severity of CVE-2022-36449 is high, with a CVSS score of 6.5.
How can a non-privileged user exploit CVE-2022-36449?
A non-privileged user can exploit CVE-2022-36449 by performing improper GPU processing operations.
Are there any known fixes for CVE-2022-36449?
At the moment, there are no known fixes for CVE-2022-36449. It is recommended to follow the vendor's security advisories for updates.