Executive brief
A vulnerability in Imagination Technologies Graphics DDK (driver development kit) could allow a standard user to access restricted areas of system memory. This occurs because the software incorrectly handles memory address calculations for very large data sets, potentially leading to system crashes or the theft of sensitive information. The issue affects devices using these graphics drivers, such as certain Android and Linux systems.
Technical details
An integer overflow vulnerability exists in the Imagination Technologies Graphics DDK when calculating physical offsets for sparse Physical Memory Resources (PMRs). When handling PMRs larger than 4 GB, the address computation may undergo 32-bit truncation, resulting in incorrect GPU Memory Management Unit (MMU) mappings. A non-privileged local user can exploit this flaw to trigger access to unintended physical memory. This can result in memory corruption or the disclosure of sensitive information from other processes or the kernel. The issue is fixed in version 26.1 RTM2.
Affected products
- Imagination Technologies Graphics DDK 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 to 25.3 RTM, 26.1 RTM1
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory