CVE-2026-45198
7.8Imagination Technologies · Graphics DDK
A trust boundary violation in the Imagination Technologies Graphics DDK allows a local attacker to corrupt GPU firmware data by manipulating pointers stored in non-secure memory.
Executive summary
A high-severity trust boundary vulnerability in Imagination Technologies Graphics DDK could allow an attacker with local kernel access to compromise GPU firmware integrity.
Vulnerability
This flaw involves an untrusted pointer dereference and a trust boundary violation where the GPU firmware consumes pointers from the Rich Execution Environment without validation. An attacker with privileged access to the local kernel can modify these pointers to corrupt internal GPU data.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high level of risk to system integrity and confidentiality. Successful exploitation allows a local attacker to bypass security boundaries, potentially leading to unauthorized data access, privilege escalation, or permanent denial of service through firmware corruption. This poses significant risk to environments relying on Trusted Execution Environments for secure processing.
Remediation
Immediate Action: Update the Imagination Technologies Graphics DDK to version 26.1 RTM2 or later to apply the necessary pointer validation fixes.
Proactive Monitoring: Monitor system logs for unusual kernel activity or unauthorized attempts to access GPU memory regions.
Compensating Controls: Ensure that access to the Rich Execution Environment kernel is strictly restricted to authorized administrators and processes to prevent the initial exploitation vector.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete compromise of the GPU firmware and the bypass of hardware-backed security boundaries, this vulnerability should be addressed as a high priority. Organizations utilizing affected Imagination Technologies drivers must schedule an update to the patched version, 26.1 RTM2, during the next available maintenance window to neutralize the risk of local kernel-based attacks.