Executive brief
A vulnerability in the Imagination Technologies GPU driver allows a non-privileged user or malicious software to bypass memory protections. By making improper system calls, an attacker can force the GPU to write data into restricted areas of physical memory, including memory used by the operating system kernel. This can lead to a complete system compromise, data corruption, or the ability to alter the behavior of the operating system.
Technical details
A memory corruption vulnerability (CWE-119) exists in the Imagination Technologies GPU Driver Development Kit (DDK) due to improper restriction of operations within memory buffer bounds. A local, non-privileged attacker can execute specific GPU system calls that trigger unauthorized write operations on restricted internal GPU buffers. This can be leveraged to achieve arbitrary physical memory writes, including pages allocated to the kernel or other drivers. The vulnerability is addressed in DDK versions following 25.2 RTM.
Affected products
- Imagination Technologies GPU DDK Up to and including 25.2 RTM
Timeline
- 2026-05-01: advisory: Initial disclosure by Imagination Technologies and NVD publication.
- 2026-06-01: patched: NVD updated with specific CPE information for DDK versions up to 25.2.