Junglewise Threat Intelligence

CVE-2026-49743: Imagination Technologies Graphics DDK use after free in kernel synchronization

CVE-2026-49743 · Severity: info · CVSS 0 · Published 2026-07-24

Technologies: Imagination Technologies Graphics DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in the Imagination Technologies Graphics DDK (Driver Development Kit) allows a non-privileged user to interfere with how the system manages GPU resources. By making specific system calls, an attacker could cause the system to use memory that has already been released, potentially leading to a system crash or unauthorized access to sensitive data. This affects devices using these specific GPU drivers, such as certain Android and Linux hardware.

Technical details

A use-after-free (UAF) vulnerability exists in the Imagination Technologies Graphics DDK kernel module. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronization primitive is not properly incremented. A local, non-privileged attacker can exploit this by destroying the exported fence to prematurely release the underlying primitive while it is still in use. This results in a read/write UAF condition in the kernel. The vulnerability is patched in versions 1.18 RTM2, 23.2 RTM2, and 26.1 RTM2.

Affected products

  • Imagination Technologies Graphics DDK 24.2 RTM2, 25.1 RTM2 to 25.3 RTM, 26.1 RTM1

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats