CVE-2026-41154

7.8

Imagination · Graphics DDK

A vulnerability in the Imagination Graphics DDK allows a local, low-privileged user to cause out-of-bounds kernel memory reads or writes via GPU API calls.

Executive summary

An out-of-bounds write vulnerability in Imagination Graphics DDK allows local users to achieve high system compromise through malicious GPU API calls.

Vulnerability

This issue is an out-of-bounds write (CWE-787) caused by incorrect buffer indexing when indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation. The attacker requires local access and low privileges with no user interaction.

Business impact

A successful exploit of this vulnerability can lead to a total compromise of confidentiality, integrity, and availability of the affected system. Because the flaw permits kernel memory reads and writes, a local attacker can potentially escalate privileges, corrupt kernel memory, or cause system crashes. The CVSS score of 7.8 establishes this as a high-severity issue requiring prompt attention to secure local environments.

Remediation

Immediate Action: Update Imagination Technologies Graphics DDK to the unaffected fixed versions, specifically 1.18 RTM2, 23.2 RTM2, 26.1 RTM2, or later.

Proactive Monitoring: Monitor systems for anomalous GPU driver behavior, unauthorized process execution, or unexpected kernel crashes.

Compensating Controls: Restrict local user access and limit the execution of untrusted applications on systems utilizing the vulnerable graphics driver.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators must treat CVE-2026-41154 with high urgency despite its local vector requirement, as kernel memory corruption frequently leads to full system takeover. Apply the vendor-supplied driver updates immediately to eliminate the out-of-bounds access vector in the sparse memory implementation.

More Imagination CVEs

Sources