Impact
A kernel‑mode error path in Imagination Technologies Graphics DDK allows a non‑privileged user to perform an out‑of‑bounds memory access and trigger a null pointer dereference. The fault causes a kernel exception that destabilises the platform and results in a denial‑of‑service condition. This vulnerability is a classic NULL pointer dereference flaw, listed as CWE‑476.
Affected Systems
The flaw exists in the Imagination Technologies Graphics DDK. No specific product versions are identified in the advisory; all installations of this DDK are potentially affected.
Risk and Exploitability
The likely attack vector is a local non‑privileged user invoking GPU system calls that trigger the error path in the driver. Such a user could cause a kernel exception that destabilises the platform, resulting in a denial‑of‑service condition. The CVSS score of 5.5 indicates a medium severity risk. The EPSS score of <1% suggests a low probability of exploitation, but the kernel‑level impact means that even a single successful exploit can crash the system. The vulnerability is not in the CISA KEV catalog, so no public exploits are known yet.
OpenCVE Enrichment