Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilit...
Description
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code could lead to incomplete
AI Analyst Comment
Remediation
Update Imagination Technologies Graphics DDK to the latest version. Monitor for exploitation attempts and review access logs.
Description Summary:
A use-after-free vulnerability in the Imagination Graphics DDK allows low-privileged local users to achieve unauthorized memory access.
Executive Summary:
A high-severity use-after-free vulnerability in Imagination Technologies Graphics DDK allows local users with low privileges to execute improper GPU system calls, potentially leading to total system compromise.
Vulnerability Details
CVE-ID: CVE-2026-7639
Affected Software: Imagination Technologies Graphics DDK
Affected Versions: Imagination Technologies Graphics DDK: 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 through 25.3 RTM, 26.1 RTM1
Vulnerability: This issue is an incomplete cleanup flaw categorized under CWE-459, triggered via improper GPU system calls requiring low privileges and local access.
Business Impact
A successful exploit permits unprivileged memory access from shader code, leading to potential data compromise, unauthorized modification, and system instability. With a CVSS score of 7.8, this high-severity flaw threatens environments where untrusted local code execution is possible, such as multi-tenant or shared workstations.
Remediation Plan
Immediate Action: Update Imagination Technologies Graphics DDK to version 26.1 RTM2 or later.
Proactive Monitoring: Monitor system and GPU driver logs for anomalous error paths or repeated failure codes within the MMU mapping logic.
Compensating Controls: Restrict local user access and prevent the execution of untrusted shader code or unverified binaries on vulnerable systems.
Exploitation Status
Public Exploit Available: No (no confirmed public exploit exists in our tracked sources).
Analyst Notes: As of Jul 10, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. Local attackers require existing low-level access to execute the malicious shader code.
Analyst Recommendation
Administrators must prioritize updating the Graphics DDK to the fixed release as soon as possible. Because local execution vectors can be leveraged in chained attacks, applying the vendor patch remains the most critical step to neutralize the risk of unauthorized physical memory access.