Impact
The bug is a time‑to‑check to time‑of‑use race condition in the rgxfw_hwperf_ufo function of the Imagination Technologies Graphics DDK. A malicious GPU driver can alter the psCmdHeader->ui32CmdSize value after the firmware has validated the command but before it uses the size. This manipulation permits the firmware to write data outside the memory region reserved for host kernel usage, leading to an unauthorized memory write and the possibility of arbitrary code execution or system instability, classified as CWE‑367.
Affected Systems
Imagination Technologies Graphics DDK is affected. No specific product versions are listed; any installation using the impacted component could be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. The EPSS score of <1% shows a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The flaw resides in kernel‑level code and requires a malicious driver running inside a host virtual machine to be executed, which limits the attack surface. Nonetheless, the ability to write outside the intended range for host kernel memory could result in arbitrary code execution or system instability if successfully exploited.
OpenCVE Enrichment