Executive brief
A vulnerability in the Imagination Technologies GPU driver allows a standard, non-privileged user to trigger improper memory operations. This could lead to the system accessing the wrong memory locations, potentially causing system instability or unauthorized access to data. This affects devices using these specific graphics drivers, such as certain mobile or embedded platforms.
Technical details
The vulnerability is classified as CWE-468 (Incorrect Pointer Scaling). It occurs because the GPU driver incorrectly scales math operations across buffers of different sizes when managing sparse memory allocations. A local, non-privileged attacker can conduct improper GPU system calls to cause mismanagement of the mapping state. This results in the product referring to incorrect memory locations. The issue is addressed in updated versions of the DDK kernel module.
Affected products
- Imagination Technologies GPU DDK DDK Releases up to and including 25.3 RTM
Timeline
- 2026-06-08: disclosed: NVD Published Date
- 2026-06-08: advisory: Imagination Technologies advisory updated