Impact
The vulnerability arises from incorrect validation of the log2 page size requested when allocating physical pages in the GPU DDK. A non-privileged user can trigger the allocation with a value that causes 4‑KiB pages to be treated as larger pages, resulting in an out‑of‑bounds read and/or write of arbitrary physical memory. This flaw is enumerated as CWE‑1284 and allows a local attacker to read or modify memory beyond the intended bounds, potentially leading to privilege escalation or system compromise.
Affected Systems
Imagination Technologies Graphics DDK. The CVE does not list specific versions; all releases of the Graphics DDK are potentially impacted.
Risk and Exploitability
The flaw is local and requires the ability to perform GPU system calls as a non‑privileged user. No public exploit is documented and the EPSS score is unavailable, making the likelihood of exploitation uncertain. However, because an attacker can exercise arbitrary physical memory access, the potential impact remains significant if the vulnerability is exploited. The CVSS score is not provided, so the exact severity cannot be quantified from the available data.
OpenCVE Enrichment