Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference in an error path.



Null pointer dereference occurs in an error path of a function running in kernel thread of execution leading to kernel exceptions, platform instability and denial of service.
Published: 2026-08-07
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A kernel‑mode error path in Imagination Technologies Graphics DDK allows a non‑privileged user to perform an out‑of‑bounds memory access and trigger a null pointer dereference. The fault causes a kernel exception that destabilises the platform and results in a denial‑of‑service condition. This vulnerability is a classic NULL pointer dereference flaw, listed as CWE‑476.

Affected Systems

The flaw exists in the Imagination Technologies Graphics DDK. No specific product versions are identified in the advisory; all installations of this DDK are potentially affected.

Risk and Exploitability

The likely attack vector is a local non‑privileged user invoking GPU system calls that trigger the error path in the driver. Such a user could cause a kernel exception that destabilises the platform, resulting in a denial‑of‑service condition. The CVSS score of 5.5 indicates a medium severity risk. The EPSS score of <1% suggests a low probability of exploitation, but the kernel‑level impact means that even a single successful exploit can crash the system. The vulnerability is not in the CISA KEV catalog, so no public exploits are known yet.

Generated by OpenCVE AI on August 7, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Imagination Technologies Graphics DDK update that corrects the null pointer dereference (CWE‑476).
  • Restart the system or reload the GPU driver after installing the update to clear any residual fault state.
  • Restrict GPU usage to applications with verified access rights, and monitor logs for kernel panics that may indicate null pointer dereference attempts.

Generated by OpenCVE AI on August 7, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech graphics Ddk
Vendors & Products Imaginationtech
Imaginationtech graphics Ddk

Fri, 07 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger OOB access and kernel null pointer dereference in an error path. Null pointer dereference occurs in an error path of a function running in kernel thread of execution leading to kernel exceptions, platform instability and denial of service.
Title GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory
Weaknesses CWE-476
References

Subscriptions

Imaginationtech Graphics Ddk
cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published:

Updated: 2026-08-07T17:54:01.911Z

Reserved: 2026-05-11T10:58:04.163Z

Link: CVE-2026-45204

cve-icon Vulnrichment

Updated: 2026-08-07T17:53:56.959Z

cve-icon NVD

Status : Received

Published: 2026-08-07T03:16:19.943

Modified: 2026-08-07T18:17:15.020

Link: CVE-2026-45204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T20:00:05Z

Weaknesses