Executive brief
A vulnerability in the Imagination Technologies Graphics DDK allows software running inside a guest virtual machine to send malicious commands to the GPU firmware. This can result in the GPU writing data outside of its assigned memory area, potentially allowing an attacker to gain higher privileges on the system. This could lead to unauthorized access to data or control over the host environment.
Technical details
A vulnerability classified as CWE-823 (Use of Out-of-range Pointer Offset) exists in the Imagination Technologies Graphics DDK. Kernel software running within a Guest VM can issue improper commands to the GPU Firmware, triggering an out-of-bounds write beyond the Guest's virtualized GPU memory boundaries. This flaw allows for memory corruption that can be leveraged for privilege escalation. The issue affects multiple DDK releases including 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 through 25.3 RTM, and 26.1 RTM1. A fix is available in version 26.1 RTM2.
Affected products
- Imagination Technologies Graphics DDK 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 to 25.3 RTM, 26.1 RTM1
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory