CVE-2022-38181
Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
- Published
- Oct 25, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Mar 30, 2023
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 96.3%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
Sources
6- CVE_2022_38181_GazelleExploit
CVE-2022-38181 POC for FireTV 3rd gen Cube (gazelle)
- CVE_2022_38181_RavenExploit
CVE-2022-38181 POC for FireTV 2nd gen Cube (raven)
- amazon-mustang-hackExploit
Kernel exploit research achieving temporary root on Amazon Fire 7 (Fire OS 7.3.3.1) via the Mali kbase JIT use-after-free CVE-2022-38181, with a modprobe_path overwrite chain.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.