CVE-2022-22706 is a local privilege-escalation vulnerability in the Arm Mali GPU Kernel Driver affecting Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0. The issue allows a non-privileged user to gain write access to CPU read-only memory pages. Supporting technical analysis attributes the flaw to incorrect permission handling in the driver function kbase_jd_user_buf_pin_pages(), where write-related logic relied on GPU write permissions without properly requiring the corresponding CPU write permission checks. By abusing GPU buffer mappings and external resource job submission, an attacker can obtain a primitive to modify read-only file-backed pages in memory. Because the modified pages remain cached, privileged processes that map the same libraries or files can execute attacker-controlled changes, enabling escalation from an untrusted app context to root on affected Android devices. Arm also noted evidence of limited, targeted exploitation in the wild.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact local privilege-escalation proof of concept for CVE-2022-22706. It contains two files: a README explaining the vulnerability, exploit flow, build/run steps, and references; and a single C source file implementing the exploit. The exploit targets a flaw in the Arm Mali kbase driver where imported user pages can be pinned without write semantics while still being remapped back to userspace as CPU-writable. By importing an anonymous writable page, then replacing that virtual address with a MAP_SHARED read-only mapping of /etc/passwd before the driver pins it during JOB_SUBMIT, the exploit obtains a writable alias to the page-cache page backing /etc/passwd. It then performs a length-preserving overwrite of the root account line from 'root:x:0:0:root:/root:/bin/sh' to 'root::0:0:rootx:/root:/bin/sh', making root appear to have an empty password in cached reads. After verifying the cached modification, it completes the pending soft event, cleans up mappings, and execs '/bin/su root' to gain a root shell. The exploit is not network-based, does not include a reverse shell or remote payload, and is a real operational local exploit rather than a detector. Its main capability is page-cache-only file content corruption leading to privilege escalation, with persistence limited to the lifetime of the cached page.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An Arm Mali GPU Kernel Driver vulnerability that may elevate CPU read-only pages to writable, allowing a non-privileged user to gain write access to read-only memory; Arm states there is evidence of limited, targeted exploitation.
A Mali GPU vulnerability discussed in the context of Android/aarch64 exploitation research demonstrating page-table-adjacent exploitation techniques and payload injection into read-only shared libraries.
A high-severity privilege escalation vulnerability in the ARM Mali GPU kernel driver that can allow an unprivileged Android app to gain write access to read-only memory pages and ultimately achieve root access.
A high-severity privilege escalation vulnerability in the ARM Mali GPU kernel driver that can allow an unprivileged Android app to gain write access to read-only memory pages and ultimately achieve root access.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.