Executive brief
A vulnerability in Imagination Technologies graphics drivers could allow a standard user to gain unauthorized write access to protected system memory and files. This component is responsible for managing how applications interact with the device's graphics hardware on Linux and Android systems. An attacker could exploit this to modify sensitive data or bypass security restrictions on the device.
Technical details
A vulnerability exists in the Imagination Technologies Graphics DDK (Driver Development Kit) for Linux and Android due to improper handling of GPU memory reservation protections (CWE-280/CWE-20). A local, non-privileged attacker can execute specific GPU system calls to bypass memory protections, gaining write permissions to user-mode memory and files that are intended to be read-only. This flaw allows for unauthorized data modification and potential privilege escalation. The issue is addressed in DDK release 26.1 RTM.
Affected products
- Imagination Technologies Graphics DDK 1.18 RTM, 23.2 RTM, 24.1 RTM to 24.2 RTM, 25.1 RTM to 25.3 RTM
Timeline
- 2026-04-17: disclosed
- 2026-04-17: advisory