Junglewise Threat Intelligence

CVE-2026-49744: Imagination Technologies Graphics DDK out-of-bounds write in GPU Firmware

CVE-2026-49744 · Severity: info · CVSS 0 · Published 2026-07-24

Technologies: Imagination Technologies Graphics DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in Imagination Technologies Graphics DDK allows software running inside a guest virtual machine to bypass security boundaries. By sending improper commands to the GPU firmware, a malicious user or malware could write data outside of the guest's assigned memory. This could lead to a complete escape from the virtual machine, potentially allowing an attacker to gain unauthorized access to the host system or other virtual machines.

Technical details

An out-of-bounds write vulnerability (CWE-823) exists in the Imagination Technologies Graphics DDK. Kernel-mode software (KMD) within a guest virtual machine can issue malformed or improper commands to the GPU firmware, triggering memory writes outside of the guest's allocated virtualized GPU memory space. This flaw allows for privilege escalation and a virtual machine escape. The vulnerability affects multiple versions of the DDK across Linux and Android platforms, specifically up to version 25.3 RTM. Version 26.1 RTM1 is reported as unaffected.

Affected products

  • Imagination Technologies Graphics DDK 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 to 25.3 RTM

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats