Executive brief
A vulnerability in the Imagination Technologies Graphics DDK (Driver Development Kit) allows a non-privileged user to trigger a memory error. This driver is used to manage graphics processing units (GPUs) in various devices, including those running Linux and Android. An attacker could exploit this to cause system instability or potentially gain unauthorized access to sensitive memory areas.
Technical details
A use-after-free (UAF) vulnerability exists in the Imagination Technologies Graphics DDK due to improper cleanup in an error path during GPU system calls. Specifically, physical memory allocated for Memory Management Unit (MMU) page tables can be accessed after being freed if a specific error path is triggered. This flaw allows a non-privileged local user to conduct improper GPU system calls to cause memory corruption. The vulnerability affects several RTM versions of the DDK on Linux and Android platforms, and is addressed in version 26.1 RTM.
Affected products
- Imagination Technologies Graphics DDK 1.18 RTM, 23.2 RTM, 24.2 RTM, 25.1 RTM to 25.3 RTM
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory