Impact
The vulnerability allows a host virtual machine kernel to issue unchecked commands to GPU firmware, resulting in an arbitrary write to GPU registers. This flaw stems from unsanitized pointers in the Graphics DDK, representing a CWE-280 weakness, and enables the driver to perform register operations that the host process would normally be restricted from modifying.
Affected Systems
The vendor Imagination Technologies, specifically its Graphics DDK, is affected. All builds of this DDK that contain the vulnerable code path may be impacted; no specific version range is specified absence of specific version ranges, it is inferred that all builds containing the vulnerable code path may be impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is less than 1%, indicating limited evidence of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is local to the host virtualization environment; the attacker must have privileged access to the host VM kernel and to the GPU driver. Successful exploitation could allow privilege escalation on the host system.
OpenCVE Enrichment