CVE-2026-7639
7.8Imagination Technologies · Graphics DDK
A use-after-free vulnerability in the Imagination Graphics DDK allows low-privileged local users to achieve unauthorized memory access.
Executive summary
A high-severity use-after-free vulnerability in Imagination Technologies Graphics DDK allows local users with low privileges to execute improper GPU system calls, potentially leading to total system compromise.
Vulnerability
This issue is an incomplete cleanup flaw categorized under CWE-459, triggered via improper GPU system calls requiring low privileges and local access.
Business impact
A successful exploit permits unprivileged memory access from shader code, leading to potential data compromise, unauthorized modification, and system instability. With a CVSS score of 7.8, this high-severity flaw threatens environments where untrusted local code execution is possible, such as multi-tenant or shared workstations.
Remediation
Immediate Action: Update Imagination Technologies Graphics DDK to version 26.1 RTM2 or later.
Proactive Monitoring: Monitor system and GPU driver logs for anomalous error paths or repeated failure codes within the MMU mapping logic.
Compensating Controls: Restrict local user access and prevent the execution of untrusted shader code or unverified binaries on vulnerable systems.
Exploitation status
Public Exploit Available: No (no confirmed public exploit exists in our tracked sources).
Analyst recommendation
Administrators must prioritize updating the Graphics DDK to the fixed release as soon as possible. Because local execution vectors can be leveraged in chained attacks, applying the vendor patch remains the most critical step to neutralize the risk of unauthorized physical memory access.