Description
Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls.



When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.
Published: 2026-07-10
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect index calculation in the CMA cleanup path of the Imagination Technologies Graphics DDK causes out‑of‑bounds reads or writes to kernel memory when GPU API calls free pages larger than 4 kB. The flaw can expose corrupt critical kernel structures, leading to potential confidentiality or integrity breaches if an attacker can trigger the offending code path.

Affected Systems

Only devices that include the Imagination Technologies Graphics DDK are affected. No specific product versions are listed, so any product that includes the DDK is potentially vulnerable.

Risk and Exploitability

The EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, indicating a low probability of active exploitation at present. The CVSS score of 7.8 reflects the severity of kernel out-of-bounds memory access that can be triggered via GPU API calls from a non-privileged user. The exploit would allow an attacker to read or overwrite kernel memory if they can invoke the freeing logic for pages larger than 4 kB.

Generated by OpenCVE AI on July 31, 2026 at 12:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a newer version of the Imagination Technologies Graphics DDK that contains the patch for the CMA cleanup bug as soon as it becomes available.
  • If a patch cannot be applied immediately, restrict the use of GPU API functions to privileged users or disable the sparse memory cleanup path if the driver or operating system provides a way to do so.
  • Continuously monitor kernel logs for GPU-related oopses or segmentation faults that indicate out-of-bounds access attempts, and investigate any anomalies promptly.

Generated by OpenCVE AI on July 31, 2026 at 12:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech graphics Ddk
Vendors & Products Imaginationtech
Imaginationtech graphics Ddk

Fri, 10 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Description Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.
Title GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse
Weaknesses CWE-787
References

Subscriptions

Imaginationtech Graphics Ddk
cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published:

Updated: 2026-07-13T18:55:25.696Z

Reserved: 2026-04-17T16:26:03.730Z

Link: CVE-2026-41154

cve-icon Vulnrichment

Updated: 2026-07-13T18:19:51.649Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T13:00:10Z

Weaknesses