Impact
The vulnerability is a write use‑after‑free that occurs when the Graphics DDK does not correctly increment the reference count of a synchronization primitive after exporting a fence. When the exported fence is destroyed, the underlying object is released prematurely, allowing kernel memory corruption. This flaw is classified under CWE‑416 and can enable an attacker to manipulate kernel state and potentially elevate privileges.
Affected Systems
Imagination Technologies Graphics DDK is affected. No specific release or version numbers are provided in the advisory, so all builds of the Graphics DDK that implement the described GPU kick function may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is less than 1%, indicating a low probability of automated exploitation. The vulnerability is not yet listed in CISA’s KEV catalog. Based on the advisory, the attack requires a non‑privileged user that can execute custom GPU calls, making it a local or user‑level attack. If an attacker succeeds, the kernel memory corruption could lead to privilege escalation.
OpenCVE Enrichment