CVE-2022-38181 is a use-after-free vulnerability in the Arm Mali GPU kernel driver caused by mishandling GPU memory operations. A local unprivileged user can perform GPU memory operations that access memory after it has been freed. Affected driver lines are Bifrost r0p0 through r38p1 and r39p0; Valhall r19p0 through r38p1 and r39p0; and Midgard r4p0 through r32p0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This is a 28-file, standalone Android kernel-exploitation research repository targeting a tightly profiled Amazon Fire 7 9th-gen (mustang) device. Its operational path is run.sh, which optionally builds poc/stage3.c and poc/su.c, transfers them through ADB, then retries the exploit across device reboots. The primary CVE-2022-38181 implementation uses /dev/mali0 kbase ioctl operations to create and evict a JIT region, reclaims the resulting freed kmalloc-96 object with controlled inotify event-name allocations, and turns kbase_jit_free list unlink writes into a redirect of an IPv4 LOCAL_OUT netfilter hook. The forged hook calls commit_creds(init_cred), after which post-exploitation code disables SELinux enforcement and installs a setuid helper at /data/metrics/su. Hard-coded kernel addresses make it specific to the documented 4.9.117 build, and the heap reclaim is acknowledged as probabilistic. The poc directory also contains earlier CVE-2022-38181 lifecycle/race/UAF validation stages plus two experimental GhostLock CVE-2026-43499 futex PI/rtmutex stack-UAF attempts. The GhostLock work is described as parked and is not the runner's main route. rootcmd.sh is a post-root cleanup script targeting Amazon Venezia package processes and data. The tools directory contains ELF/kernel-disassembly and symbol/address-resolution helpers, inotify heap-spray measurement programs, and MediaTek preloader HID utilities. The latter identify USB 1949:20ff, probe the standard MTK byte-pair handshake, and implement guarded read32/write32 protocol operations that could potentially enable raw eMMC research, but are separate from the main local kbase exploit.
This repository is a real local Android kernel privilege-escalation project centered on Arm Mali GPU driver vulnerabilities, primarily CVE-2022-38181, adapted for an Amazon Fire HD 10 (KFTRWI/trona) running Fire OS 7.3.2.6 on MT8183 with Mali-G72/kbase r14p0. It is not a framework module; it is a standalone research/exploit repo with documentation, PoCs, diagnostics, and automation scripts. Repository structure: top-level markdown files (README.md, HANDOFF.md, REVIEW.md, STATE.md, blog.md) document the research history, exploit design, review findings, and final chain. The poc-28663/ directory contains the actual C code: low-level headers (mali.h, mali_trona.h), older leak PoCs (mali_poc.c, mali_poc_trona.c), validation tools (gpu_test.c, alias_write_test.c, dump_probe.c, diag*.c), staged exploit-development programs (jit_trigger.c, stageb*.c, stagec.c, diagd.c), and the main exploit (exploit_trona.c). Bash scripts (grind.sh, grind2.sh, root_grind.sh) automate repeated deployment and reboot-loop grinding over ADB. Main exploit capability: exploit_trona.c implements a full local root chain. It opens /dev/mali0, initializes a Mali context, triggers the CVE-2022-38181 JIT allocator use-after-free by marking a JIT region DONT_NEED and forcing shrinker reclamation, sprays replacement regions, aliases them, and uses GPU WRITE_VALUE jobs to corrupt GPU page-table entries. The documented final chain then derives arbitrary physical read/write, locates kernel anchors such as init_task, init_cred, modprobe_path, and selinux_enforcing, disables SELinux, overwrites credentials/capabilities, and abuses modprobe_path to execute a helper script from /data/local/tmp as root. Supporting code confirms each primitive independently: jit_trigger.c proves the JIT region can be reclaimed while still referenced; stageb/stagec/diagd validate replacement and freeing behavior; gpu_test.c validates GPU command submission; alias_write_test.c proves GPU writes through a PROT_NONE alias affect shared backing; dump_probe.c parses GPU MMU dumps; diag/diag2 investigate driver quirks and memory-pool behavior. The bash grinders repeatedly push the exploit to /data/local/tmp/exploit_trona via adb, execute it, monitor logs, and reboot on crashes/timeouts. Attack surface and targeting are strictly local: the exploit requires code execution on the device and access to the Mali device node. There are no remote C2 or network callbacks in the exploit code. The most fingerprintable artifacts are local device files (/dev/mali0, /dev/binder, /dev/kmsg, /sys/fs/selinux/enforce), on-device payload paths under /data/local/tmp, and hardcoded physical/kernel addresses specific to the targeted firmware build. Overall, this is an operational exploit-development repository for a device-specific Android local root chain, with substantial engineering notes and multiple intermediate PoCs rather than a single minimal exploit.
This repository is a standalone Android application that operationalizes a local privilege-escalation exploit chain for a very specific target device: the au/KDDI Xiaomi XIG04 ('aristotle') running Android 12. Its purpose is not remote compromise; instead, it is a device-owner utility that uses a bundled native exploit payload to obtain temporary root and then enable ADB/developer settings on the phone. Repository structure: the main logic lives in app/src/main/java/com/soralis/aristotle/malienable/. MainActivity.kt provides a simple single-screen UI with buttons to run the exploit, view/share/clear logs, and display progress. ExploitRunner.kt is the core wrapper/orchestrator: it stages preload.so from APK assets into the app's private files directory, verifies it looks like an ELF, chmods it, launches /system/bin/true with LD_PRELOAD pointing to the staged library, then probes for a working su binary and uses it to run privileged settings commands. The native exploit itself is not present in this repository; it is expected to come from the exploit/ git submodule and be built into app/src/main/assets/exploit/preload.so by the Gradle task buildExploitSo defined in app/build.gradle. Exploit capabilities: the app acts as a launcher for a native shared-object payload that exploits CVE-2022-38181 (per README and code comments) in the Android kernel Futex-PI path. The payload is described as obtaining temporary root, self-installing su components at known filesystem paths, and enabling the wrapper app to execute commands as root. After successful exploitation, the wrapper enables development_settings_enabled and adb_enabled and restarts adbd. It also maintains a persistent crash-surviving log file (preload.log) in the app files directory and exposes it through Android FileProvider for sharing. Notable implementation details: the project includes a placeholder asset instead of a real payload so the app can still build without the exploit submodule. The build system automatically compiles the native payload from the submodule using the Android NDK and embeds it as an uncompressed asset. The code is clearly intended for local execution on the target handset only, with hardcoded assumptions about architecture, OS version, and expected su installation paths. No network C2, remote callback, or scanning behavior is present in the analyzed repository.
Repository contains a working local Android kernel privilege-escalation exploit for CVE-2022-38181 in the Arm Mali GPU kbase driver, plus an adapted port for Xiaomi XIG04. Structure is split between `poc-upstream/` (original Security Lab PoC and headers) and `src/` (modified port). The main exploit logic is in `src/mali_shrinker_mmap.c`, with `build.sh` compiling either a standalone arm64 binary (`mali_xig04`) or a `preload.so` variant intended to run via LD_PRELOAD into `/system/bin/true` from an app harness. Exploit capability: it abuses a Mali JIT memory use-after-free/shrinker interaction to reclaim freed pages as page tables, then rewrites page-table entries to map arbitrary physical memory into the GPU address space, yielding arbitrary kernel read/write. It then patches SELinux-related code/data (`avc_denied`, `sel_read_enforce`) and uses `init_cred`/`commit_creds`-style credential manipulation to obtain root. Upstream variants spawn `sh`; the XIG04 port instead runs Android commands to enable ADB and restart `adbd`. Targeting is highly device/build specific. `PORT_NOTES.md` documents the XIG04 target: Android 12, MT6895, Mali-G610, kbase r32p1, with hardcoded symbol RVAs and a configurable `kernel_base`. The source adds XIG04-specific fingerprint/offset handling and notes uncertainty around the physical kernel load base. The exploit is not a scanner or detector; it is real exploit code with a concrete post-exploitation payload. Overall maturity is OPERATIONAL: it includes a usable payload and build/run workflow, but remains tightly coupled to specific firmware offsets and device conditions rather than being broadly weaponized.
This repository contains a functional exploit for CVE-2022-38181, targeting the ARM Mali GPU kernel driver on the Amazon FireTV 2nd gen Cube (FireOS, 32-bit userspace, Bifrost r16p0, Linux kernel 4.9.113). The main exploit logic is implemented in 'mali_shrinker_mmap32.c', which interacts directly with the '/dev/mali0' device node to trigger a vulnerability in the kernel driver. The exploit achieves arbitrary kernel code execution, disables SELinux, and spawns a root shell, effectively granting full control over the device. The repository includes several large header files ('mali.h', 'mali_base_jm_kernel.h', 'midgard.h') that provide necessary structures and constants for interacting with the Mali driver. The README provides compilation and usage instructions, emphasizing the need to run the exploit shortly after device boot for maximum reliability. The attack vector is local, requiring code execution on the device, and the main fingerprintable endpoint is the '/dev/mali0' device file.
This repository contains a functional local privilege escalation exploit for CVE-2022-38181, targeting the ARM Mali GPU kernel driver on the Amazon FireTV 3rd gen Cube (FireOS). The exploit is a fork of a Pixel 6 proof-of-concept, adapted for FireOS's 32-bit userspace. The main exploit logic resides in 'mali_shrinker_mmap32.c', which interacts directly with the '/dev/mali0' device node to trigger a use-after-free or similar memory corruption in the kernel driver. The exploit includes hardcoded offsets for various FireOS kernel builds, allowing it to locate and overwrite critical SELinux and credential management functions in kernel memory. Upon successful exploitation, the payload disables SELinux enforcement and spawns a root shell, granting full control over the device. The repository also includes several large header files ('mali.h', 'mali_base_jm_kernel.h', 'midgard.h') that provide necessary structures and constants for interacting with the Mali driver. The exploit must be run shortly after device boot for maximum reliability. No network endpoints are involved; the attack vector is purely local, requiring code execution on the target device.
This repository contains a local privilege escalation exploit targeting CVE-2022-38181 in the ARM Mali GPU kernel driver on Android devices. The exploit is implemented in C, with supporting header files for interacting with the Mali driver and GPU memory structures. The main exploit logic is in 'src/mali_shrinker.c', which performs a series of memory operations via the /dev/mali0 device node to corrupt kernel memory and achieve arbitrary code execution in the kernel context. Hardcoded kernel offsets are provided for several Fire OS versions, indicating the exploit is tailored for specific device/firmware combinations. The payload disables SELinux enforcement and escalates privileges to root, spawning a shell upon success. The 'build.sh' script is used to compile the exploit for a target device using the Android NDK. No network endpoints are present; the attack vector is local, requiring code execution on the target device. The repository is structured with a build script, several C header files for Mali GPU structures, and the main exploit source file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.