Executive brief
A vulnerability in Imagination Technologies GPU drivers could allow software running within a virtual machine to bypass security boundaries. By sending improper commands to the GPU hardware, a compromised guest system could write data to memory areas it should not be able to access, potentially leading to a full system compromise or data corruption. This affects devices using specific GPU firmware and drivers, typically found in mobile and embedded systems.
Technical details
A logic error in the address translation mechanism of the Imagination Technologies GPU DDK allows kernel-mode software within a Guest or Host VM to perform arbitrary writes to firmware memory. By posting malformed or improper commands to the GPU firmware, an attacker with kernel-level privileges can trigger out-of-bounds writes (CWE-823) outside of the intended GPU memory segments. This vulnerability effectively allows a compromised host or guest to subvert GPU hardware protections. The issue is addressed in DDK releases following 25.3 RTM.
Affected products
- Imagination Technologies GPU DDK DDK Releases up to and including 25.3 RTM
Timeline
- 2026-06-01: disclosed: CVE published by NVD and Imagination Technologies