Executive brief
A vulnerability in Imagination Technologies GPU drivers allows a standard, non-privileged user to execute malicious commands that corrupt the system's core memory (kernel heap). This could allow an attacker to crash the device or potentially gain full control over the operating system. The issue affects devices using these specific graphics drivers, such as certain mobile or embedded systems.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Imagination Technologies GPU DDK kernel module. A local, non-privileged attacker can trigger this vulnerability by creating specific resource types and providing a crafted set of parameters to the affected GPU interface. This results in improper GPU system calls that lead to kernel heap memory corruption. Successful exploitation could lead to local privilege escalation or a system crash. The vendor has addressed this in DDK releases following 25.3 RTM.
Affected products
- Imagination Technologies GPU DDK DDK Releases up to and including 25.3 RTM
Timeline
- 2026-06-08: disclosed
- 2026-06-08: advisory