Impact
The vulnerability resides in the GPU driver’s use of a pointer from non‑secure Rich Execution Environment memory for core memory storage during firmware initialization. An attacker who controls the REE kernel can alter that pointer, causing the GPU firmware to use attacker‑controlled data. This can corrupt internal firmware data, potentially affecting GPU operation. The weakness is identified as CWE‑822, relating to the use of untrusted pointers.
Affected Systems
Imagination Technologies Graphics DDK is affected. No specific versions are listed, so any installation that contains the referenced firmware component may be vulnerable. The vulnerability applies to systems running a non‑secure operating system on platforms that support a Trusted Execution Environment.
Risk and Exploitability
Based on the description, the likely attack vector is local privileged execution within the Rich Execution Environment. The attack requires control of the REE kernel, therefore it is limited to local privileged contexts. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalogue, indicating no publicly known exploit. The CVSS score of 7.8 denotes high severity. While the explicit capabilities an attacker could gain are not detailed, the fact that the attacker can manipulate firmware data suggests a serious risk in environments where the REE kernel can be compromised.
OpenCVE Enrichment