Impact
A vulnerability in Imagination Technologies' Graphics DDK allows a non-privileged user to perform GPU system calls that ultimately trigger memory leaks and double free events. These improper deallocation paths can lead to kernel heap corruption, potentially destabilizing the operating system or allowing an attacker to gain additional write or execute privileges within kernel memory.
Affected Systems
Imagination Technologies Graphics DDK is the affected product. Detailed version information was not provided, so any installation of the Graphics DDK may be vulnerable until an official patch is released.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity for this kernel heap corruption flaw, and the EPSS score of less than 1% suggests that exploitation is unlikely at present. Nevertheless, any unpatched system that accepts GPU calls from untrusted users remains at risk, as the double‑free and memory‑leak conditions could cause kernel memory corruption and potential escalation.
OpenCVE Enrichment