Junglewise Threat Intelligence

CVE-2026-41156: Imagination Technologies Graphics DDK use after free in GPU system calls

CVE-2026-41156 · Severity: info · CVSS 0 · Published 2026-06-19

Technologies: Imagination Technologies Graphics DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in Imagination Technologies graphics drivers could allow a non-privileged user to cause a system crash or potentially gain unauthorized access. The issue occurs when the system's main processor (CPU) and graphics processor (GPU) fail to coordinate memory usage correctly, leading to a memory corruption scenario. This could impact the stability of devices like smartphones or embedded systems and potentially be used as a stepping stone for further attacks.

Technical details

A write use-after-free (UAF) vulnerability exists in the Imagination Technologies Graphics DDK due to improper management of shared memory resources between the CPU and GPU. Specifically, a CPU thread (driver) may free a memory page before the GPU thread (firmware) has finished its access operations. A local, non-privileged attacker can trigger this condition by making improper GPU system calls. This race condition or mismanagement of resource lifecycles can lead to memory corruption. The issue is addressed in DDK version 26.2 RTM.

Affected products

  • Imagination Technologies Graphics DDK 1.18 RTM, 23.2 RTM, 24.2 RTM, 25.1 RTM to 25.3 RTM, 26.1 RTM

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory

References

Related threats