Executive brief
A vulnerability in Imagination Technologies Graphics DDK allows software running inside a guest virtual machine to bypass security boundaries. By sending improper commands to the GPU firmware, a malicious user or malware could write data outside of the guest's assigned memory. This could lead to a complete escape from the virtual machine, potentially allowing an attacker to gain unauthorized access to the host system or other virtual machines.
Technical details
An out-of-bounds write vulnerability (CWE-823) exists in the Imagination Technologies Graphics DDK. Kernel-mode software (KMD) within a guest virtual machine can issue malformed or improper commands to the GPU firmware, triggering memory writes outside of the guest's allocated virtualized GPU memory space. This flaw allows for privilege escalation and a virtual machine escape. The vulnerability affects multiple versions of the DDK across Linux and Android platforms, specifically up to version 25.3 RTM. Version 26.1 RTM1 is reported as unaffected.
Affected products
- Imagination Technologies Graphics DDK 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 to 25.3 RTM
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory