CVE-2022-22057 is a use-after-free vulnerability in the graphics fence implementation of multiple Qualcomm Snapdragon platforms, including Auto, Compute, Connectivity, Industrial IoT, Mobile, and Wearables. The vulnerability arises from a race condition that occurs when a fence file descriptor is closed while the graphics timeline is being destroyed, leading to the use of freed memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This is a 97-file GPLv3 local-kernel exploitation research repository, not a framework module. Its core is ghostlock_repo/ghostlock_oppo_final.c plus ghostlock_repo/ghostlock_arm32.c/.h. These C programs implement/reference exploitation of CVE-2026-43499 ('GhostLock'), described as an ARM32 Linux rtmutex/futex priority-inheritance stack use-after-free caused by clearing pi_blocked_on for current rather than the waiter owner during proxy-lock rollback. The proposed chain uses FUTEX_WAIT_REQUEUE_PI and FUTEX_CMP_REQUEUE_PI across coordinated threads to leave a dangling rt_mutex_waiter on the waiter thread's kernel stack. Controlled deep-stack user-copy syscalls are then intended to overwrite the stale waiter fields, force an rtmutex chain walk to enqueue it into a fake lock, and store the dangling stack address into a writable callback slot. The callback is subsequently invoked through an ioctl/read path to execute stamped ARM32 code. For the OPPO 00522 adaptation, hard-coded addresses include init_task (0xC1A112C0), init_cred (0xC1A174D0), commit_creds (0xC0148C60), device_switch_proc_fops (0xC1ABA320), a fake lock around 0xC1ABA338/0xC1ABA344 depending on report revision, and selinux_state at 0xC1D5A720 with enforcing at +1. The intended payload disables SELinux and clears the armed callback; the Huawei reference instead calls commit_creds(init_cred) and starts a root shell. The documentation contains conflicting intermediate research conclusions and address/layout revisions, but its top-level README and ghostlock_repo README consistently state the final practical conclusion: on the actual OPPO 5.4.134-perf-00522 msm-5.4 build, the chain-walk/enqueue path crashes the kernel, while candidate /proc/switch/{lcd,mt,tp} triggers are denied by SELinux. It should therefore be treated as a detailed failed-target research case and a potentially adaptable proof-of-concept mechanism, not a reliable exploit for that OPPO build. Most remaining files are Python ARM32 reverse-engineering utilities, kallsyms extractors, kernel-stack-depth/copy scanners, disassembly logs, symbol tables, and reports. The _rev/ subtree separately analyzes Qualcomm KGSL interfaces and historical candidates including CVE-2022-22057-style mmap/gpuobj lifetime issues and GPU-side command/race concepts. Those reports explicitly rule out several CPU-side KGSL theories on this exact build (for example, map_user_mem TOCTOU because get_user_pages is protected by mmap locking) and identify firmware, refcount, or mitigation constraints. heota_query.py is an ancillary OTA-retrieval tool: it implements the OPPO HeyOTA AES-CTR request format and queries iota.coloros.com to obtain firmware information for offline kernel extraction. Fetch scripts retrieve external GitHub comparison code; they are auxiliary research tooling rather than exploit runtime dependencies.
This repository is an operational exploit for CVE-2022-22057, a vulnerability in the Qualcomm kgsl GPU driver on Android. The exploit targets Samsung Galaxy Z Flip 3 (SM-F926U) devices running a specific firmware version. The codebase is organized into several directories: - `libtimeline/jni/`: Contains JNI/C++ code, build scripts, and a bundled copy of BoringSSL headers for cryptographic operations. The main entry point for persistence is `libtimeline.so`, which acts as a startup daemon. - `timeline/source/`: Contains C source files implementing the core exploit logic, including heap spraying, fake object creation, and kernel memory manipulation. - `timeline/Makefile`: Provides build instructions for cross-compiling the exploit for Android ARM64. The exploit works by leveraging a bug in the kgsl driver to gain arbitrary kernel memory read/write from an untrusted app context. It disables SELinux and spawns a root shell on 127.0.0.1:6969, accessible via netcat. The exploit is not persistent across reboots and is considered highly insecure, as it leaves a root shell open on a local port. The README provides detailed instructions for compiling, deploying, and using the exploit, as well as caveats and warnings about device stability and security risks. Key fingerprintable endpoints include the use of `/data/local/tmp/timeline`, `/data/local/tmp/libtimeline.so`, and the local TCP port 6969 for root shell access. The exploit is operational and provides a working root shell if the device is vulnerable and properly configured.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.