VYPR
Unrated severityNVD Advisory· Published Mar 8, 2023· Updated Mar 5, 2025

CVE-2022-46394

CVE-2022-46394

Description

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r39p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A use-after-free vulnerability in Arm Mali GPU Kernel Driver allows a non-privileged user to access freed memory, affecting Valhall r39p0-r41p0 and Avalon r41p0.

Vulnerability

The Arm Mali GPU Kernel Driver contains a use-after-free vulnerability (CVE-2022-46394) where a non-privileged user can perform improper GPU processing operations to access already freed memory [1][2]. This affects Valhall GPU kernel driver versions r39p0 through r41p0, and Avalon GPU kernel driver version r41p0, prior to the fixed version r42p0.

Exploitation

An attacker with local non-privileged access to a system using an affected Mali GPU driver can trigger the vulnerability by submitting specially crafted GPU processing operations. The exact sequence of operations leads to the use of a memory object after it has been freed, resulting in a use-after-free condition.

Impact

Successful exploitation allows the attacker to read or write freed memory, potentially leading to information disclosure of sensitive data or escalation of privileges. The attacker gains access to memory that should be protected, which could be leveraged for further compromise.

Mitigation

Arm has released driver version r42p0 which fixes the vulnerability for both Valhall and Avalon architectures [1][2]. Users should update their GPU kernel driver to r42p0 or later. No workarounds have been publicly documented.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Arm/Mali GPU Kernel Driverdescription
  • Range: Valhall r39p0 through r41p0 before r42p0, Avalon r41p0 before r42p0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.