Junglewise Threat Intelligence

CVE-2026-41154: Imagination Technologies Graphics DDK out-of-bounds access in sparse memory logic

CVE-2026-41154 · Severity: info · CVSS 0 · Published 2026-07-10

Technologies: Imagination Technologies Graphics DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in the Imagination Technologies Graphics DDK (Driver Development Kit) could allow a non-privileged user to cause system instability or access restricted memory. The issue occurs when the driver handles specific graphics API calls related to memory management. An attacker could exploit this to read or write to sensitive kernel memory, potentially leading to a full system compromise or data theft.

Technical details

An out-of-bounds (OOB) read/write vulnerability exists in the Imagination Technologies Graphics DDK due to incorrect buffer indexing. The flaw is located within the page freeing logic of the sparse memory implementation when indexing pages larger than 4kB. A local, non-privileged attacker can trigger this vulnerability through specific GPU API calls. This can result in kernel memory corruption or information disclosure. The issue has been addressed in DDK versions 1.18 RTM2, 23.2 RTM2, and 26.1 RTM2.

Affected products

  • Imagination Technologies Graphics DDK 24.2 RTM2, 25.1 RTM2 to 25.3 RTM, 26.1 RTM1

Timeline

  • 2026-07-10: advisory: NVD publication date
  • 2026-07-10: disclosed: Initial disclosure by Imagination Technologies

References

Related threats