CVE-2026-21733
7.3Imagination Technologies · Graphics DDK
A vulnerability in the Imagination Technologies Graphics DDK allows a local, non-privileged user to gain unauthorized write access to read-only user-mode memory and files via improper GPU system calls.
Executive summary
A critical local privilege escalation flaw in Imagination Technologies Graphics DDK allows non-privileged users to bypass memory protections and gain unauthorized write access.
Vulnerability
This vulnerability, categorized under CWE-280, stems from the improper handling of GPU memory reservation protections. A local attacker with low privileges can exploit these flawed system calls to overwrite protected, read-only memory and files.
Business impact
The ability for a non-privileged user to gain write access to restricted memory and files poses a significant threat to system integrity and confidentiality. Successful exploitation could allow an attacker to modify system processes, escalate privileges, or corrupt critical data. Given the CVSS score of 7.3, this high-severity vulnerability represents a substantial risk to any environment relying on affected GPU hardware.
Remediation
Immediate Action: Update the Imagination Technologies Graphics DDK to version 26.1 RTM or later to resolve the underlying memory reservation flaw.
Proactive Monitoring: Audit system logs for unusual GPU-related system calls or unauthorized attempts to access protected memory regions by standard user accounts.
Compensating Controls: Restrict local access to systems using the vulnerable DDK and enforce the principle of least privilege for all local user accounts to limit the potential impact of a compromise.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing the affected Imagination Technologies Graphics DDK should prioritize upgrading to version 26.1 RTM immediately. Because this vulnerability facilitates privilege escalation and unauthorized file modification, patching is essential to maintain the security posture of affected workstations and servers. Monitor vendor channels for any additional guidance regarding driver deployment.