Junglewise Threat Intelligence

CVE-2026-41158: Imagination Technologies GPU DDK use after free in physical memory management

CVE-2026-41158 · Severity: info · CVSS 0 · Published 2026-06-12

Technologies: Imagination Technologies GPU DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in Imagination Technologies GPU drivers allows a standard, non-privileged user to perform unauthorized actions on the system's physical memory. By making specific GPU system calls, an attacker could write data to memory locations that have already been freed, potentially leading to system instability or unauthorized data modification. This could allow a malicious application to interfere with other processes or the operating system itself.

Technical details

A use-after-free (UAF) vulnerability exists in the Imagination Technologies GPU DDK kernel module. The issue stems from physical memory being allocated and freed without utilizing the deferred free mechanism, allowing the GPU to perform read/write operations on resources after the kernel module has officially freed them. A local, non-privileged attacker can exploit this by conducting specific GPU system calls to target arbitrary freed physical pages. This can lead to memory corruption or potentially broader system compromise. The vendor has addressed this in the DDK kernel module by ensuring resources are managed correctly via the deferred free mechanism.

Affected products

  • Imagination Technologies GPU DDK DDK Releases up to and including 25.3 RTM

Timeline

  • 2026-06-12: disclosed: NVD publication date
  • 2026-06-12: advisory: Imagination Technologies advisory updated

References

Related threats