Executive brief
A vulnerability in Imagination Technologies Graphics DDK allows software running within a virtual machine to issue improper commands to the GPU firmware. This can result in unauthorized reading or writing of system memory outside of the virtual machine's assigned boundaries. Such an exploit could lead to a compromise of the host system's integrity or the exposure of sensitive data from other processes.
Technical details
A vulnerability classified as CWE-280 (Improper Handling of Insufficient Permissions or Privileges) exists in the Imagination Technologies Graphics DDK. Kernel-level software within a guest virtual machine can submit malformed commands to the GPU firmware, causing it to perform memory operations (reads/writes) using addresses that exceed the host kernel's permitted range. This occurs because the firmware may use passed addresses for more privileged memory accesses than the system intended to allow. The issue affects various RTM versions of the DDK on Linux and Android platforms and is resolved in version 26.2 RTM.
Affected products
- Imagination Technologies Graphics DDK 1.18 RTM, 23.2 RTM, 24.2 RTM, 25.1 RTM to 25.3 RTM, 26.1 RTM
Timeline
- 2026-06-26: disclosed
- 2026-06-26: advisory