Impact
An incorrect index calculation in the CMA cleanup path of the Imagination Technologies Graphics DDK causes out‑of‑bounds reads or writes to kernel memory when GPU API calls free pages larger than 4 kB. The flaw can expose corrupt critical kernel structures, leading to potential confidentiality or integrity breaches if an attacker can trigger the offending code path.
Affected Systems
Only devices that include the Imagination Technologies Graphics DDK are affected. No specific product versions are listed, so any product that includes the DDK is potentially vulnerable.
Risk and Exploitability
The EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, indicating a low probability of active exploitation at present. The CVSS score of 7.8 reflects the severity of kernel out-of-bounds memory access that can be triggered via GPU API calls from a non-privileged user. The exploit would allow an attacker to read or overwrite kernel memory if they can invoke the freeing logic for pages larger than 4 kB.
OpenCVE Enrichment