Junglewise Threat Intelligence

CVE-2026-41155: Imagination Technologies GPU DDK improper isolation in kernel module

CVE-2026-41155 · Severity: info · CVSS 0 · Published 2026-06-12

Technologies: Imagination Technologies GPU DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in the Imagination Technologies GPU driver could allow a malicious application to access data from other secure processes running on the same graphics processor. This flaw breaks the isolation between secure tasks, potentially leading to the theft of sensitive information or causing the graphics hardware to crash and reset. This could result in data corruption or a temporary loss of service for users of the affected device.

Technical details

An improper isolation or compartmentalization vulnerability (CWE-653) exists in the Imagination Technologies GPU DDK kernel module. The flaw allows shared secure memory allocations to be accessed across different secure GPU processes. A local attacker can exploit this to cooperatively pass data between supposedly isolated secure processes or disrupt the operation of another secure process. Such disruption can lead to image corruption and trigger GPU hardware recovery mechanisms. The vulnerability is addressed in DDK releases following 25.3 RTM.

Affected products

  • Imagination Technologies GPU DDK DDK Releases up to and including 25.3 RTM

Timeline

  • 2026-06-12: disclosed
  • 2026-06-12: advisory

References

Related threats