CVE-2022-46396: Buffer Overflow
An issue was discovered in the Arm Mali Kernel Driver. A non-privileged user can make improper GPU memory processing operations to access a limited amount outside of buffer bounds. This affects Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-46396?
CVE-2022-46396 is an issue discovered in the Arm Mali Kernel Driver, which allows a non-privileged user to make improper GPU memory processing operations and access a limited amount outside of buffer bounds.
Which software is affected by CVE-2022-46396?
CVE-2022-46396 affects Google Android devices running Arm Mali Graphics Processing Unit (GPU) drivers Valhall r29p0 through r41p0 before r42p0 and Avalon r41p0 before r42p0.
What is the severity of CVE-2022-46396?
The severity of CVE-2022-46396 is high with a CVSS score of 3.3.
How can CVE-2022-46396 be fixed?
To fix CVE-2022-46396, users should update their Arm Mali Kernel Driver to version r42p0 or later.
Where can I find more information about CVE-2022-46396?
You can find more information about CVE-2022-46396 in the Android Security Bulletin for May 2023 and the Arm Security Center's documentation on Mali GPU Driver Vulnerabilities.