Impact
A buffer overrun in the Imagination Technologies Graphics DDK allows a guest virtual machine to issue GPU commands that write data outside the virtualised GPU memory. The write occurs via an unvalidated sHWPerfCtlDMABuf GPU-VA DMA operation that targets firmware private data. The flaw can be leveraged to gain higher privileges within the host or the hypervisor environment, compromising the confidentiality, integrity, and availability of the host system.
Affected Systems
The vulnerability affects the Graphics DDK from Imagination Technologies. No specific product versions are listed, so all current releases that contain the unvalidated DMA control code may be impacted until a patch is released. The exact scope depends on the guest VM's ability to send GPU commands to the firmware.
Risk and Exploitability
The EPSS score indicates less than a 1% chance of exploitation today, and the vulnerability is not included in the CISA KEV catalog. The most likely attack path is a compromised guest VM that can execute raw GPU commands; it is inferred that the attacker can trigger the out-of-bounds write from within the VM. There is no publicly documented exploit, but the severity of the impact warrants caution. The CVSS score is 7.8, indicating moderate to high severity.
OpenCVE Enrichment