CVE-2026-22167

7.8

Imagination Technologies · Graphics DDK

A memory buffer vulnerability in Imagination Technologies Graphics DDK allows a local authenticated user to perform unauthorized GPU writes and corrupt kernel memory.

Executive summary

An improper memory buffer restriction vulnerability in the Imagination Technologies Graphics DDK allows local non-privileged users to corrupt kernel memory and alter system behavior, presenting a severe integrity and confidentiality risk.

Vulnerability

This is an improper restriction of operations within the bounds of a memory buffer, classified under CWE-119, triggered via improper GPU system calls requiring low local privileges and no user interaction.

Business impact

Successful exploitation of this flaw can lead to total compromise of system confidentiality, integrity, and availability as attackers corrupt kernel memory and manipulate platform behavior. With a CVSS score of 7.8, this high-severity vulnerability poses significant risks to enterprise systems relying on affected graphics drivers, potentially allowing local container escapes or root privilege escalation.

Remediation

Immediate Action: Update the Imagination Technologies Graphics DDK to version 26.1 RTM or later where the vulnerability is resolved.

Proactive Monitoring: Monitor local system logs for anomalous GPU driver behavior, unauthorized process executions, or unexpected kernel panics.

Compensating Controls: Restrict local shell access and apply rigorous principle of least privilege principles to limit which users can execute unprivileged software on the host.

Exploitation status

Public Exploit Available: False / unknown

Analyst recommendation

Security teams must treat this high-severity flaw with urgency despite the requirement for local execution. Administrators should prioritize upgrading affected Imagination Technologies Graphics DDK installations to version 26.1 RTM immediately to eliminate the underlying memory corruption vector.

More Imagination Technologies CVEs

Sources