LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-22706: Arm Mali GPU Kernel Driver Unspecified Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 30, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 20, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-22706 to its Known Exploited Vulnerabilities catalog on Mar 30, 2023, with a federal patch deadline of Apr 20, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write access to read-only memory pages.

CVE-2022-22706 is an unspecified vulnerability in the Arm Mali GPU Kernel Driver that lets a non-privileged user obtain write access to memory pages that should be read-only. Because the driver runs in the kernel, successful abuse can undermine memory protections and open a path to elevated privileges or further compromise on devices that rely on Mali GPUs. Defenders should treat it as a local privilege-escalation risk until the vendor advisory is reviewed and systems are confirmed patched.

The issue matters for any environment that ships Arm Mali graphics hardware—mobile devices, embedded platforms, and some server or appliance designs—because unprivileged local code can reach kernel-managed memory. Public detail beyond the CISA description is limited; confirm exact impact and affected builds against the vendor advisory.

How it works

The weakness is classified under CWE-119 (improper restriction of operations within the bounds of a memory buffer). In practical terms, the kernel driver fails to enforce intended read-only protections on certain memory pages. A non-privileged process that can interact with the Mali GPU driver may therefore write data into regions the kernel expects to remain immutable.

An attacker who already has local code execution (for example through a malicious app or a compromised user account) can leverage this write capability to alter kernel data structures or code paths. The precise trigger and memory layout are not detailed in the public summary; treat the attack surface as any interface that reaches the Mali kernel driver and verify mechanics only against the vendor advisory. No exploit code or ransomware linkage is documented for this CVE.

Am I affected? How to find it in your systems

Arm Mali GPUs appear in many Android handsets, tablets, set-top boxes, automotive systems, and other embedded Linux or Android-based platforms. Inventory starts with identifying devices or images that include Mali graphics hardware and the associated kernel driver module.

Telemetry signs of exploitation are not publicly catalogued for this CVE. Look for unexpected kernel memory faults, driver crashes, or privilege-escalation attempts originating from unprivileged processes that interact with the GPU. Correlate with process-creation and device-access logs; any confirmed anomaly should be investigated against the vendor’s guidance.

How to remediate

Apply the vendor-supplied update for the Arm Mali GPU Kernel Driver as directed by the advisory. CISA’s required action is simply to apply updates per vendor instructions; no additional public patch identifiers are provided here.

If you can't patch immediately

Until the vendor update can be installed, reduce the attack surface and increase detection.

These measures lower risk but do not eliminate it; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited kernel vulnerabilities can lead to full device compromise and subsequent data exposure. While ransomware use of this specific CVE is not documented, any confirmed exploitation should trigger standard incident-response steps: isolate the host, preserve forensic evidence, and assess whether credentials or sensitive data left the device. Organizations and individuals can also run a free exposure scan of their email addresses against known breach data sets to determine whether related accounts appear in public breach corpora and then rotate credentials accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArm · Mali Graphics Processing Unit (GPU)
WeaknessCWE-119
Added to CISA KEVMar 30, 2023
Federal patch deadlineApr 20, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities