Executive brief
A vulnerability in the Imagination Technologies GPU driver allows a standard user to trigger an out-of-bounds write in the system kernel. By making specific requests to the GPU's memory management system, a malicious application could potentially crash the device or gain elevated system privileges. This affects the stability and security of devices using these graphics drivers, such as mobile phones or embedded systems.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the Imagination Technologies GPU Driver Development Kit (DDK). The flaw is caused by incorrect indexing of internal state during sparse allocation remapping when processing GPU sparse memory API calls. A non-privileged local attacker can exploit this by issuing intentional, crafted API calls to trigger an out-of-bounds write in kernel memory. This could lead to local privilege escalation (LPE) or a system-wide denial of service (kernel panic). While the advisory confirms the vulnerability, specific affected version ranges were not detailed in the provided June 2026 entry.
Affected products
- Imagination Technologies GPU DDK Not specified
Timeline
- 2026-06-12: disclosed: CVE published by NVD and Imagination Technologies