Impact
The flaw is a use‑after‑free in the Graphics DDK’s MMU mapping logic, allowing a non‑privileged user to trigger a sequence of malformed GPU system calls that causes incomplete cleanup of internal driver state. This permits the attacker to read the contents of physical memory through shader code. The weakness is identified as CWE‑459.
Affected Systems
Imagination Technologies Graphics DDK hardware drivers are affected. No specific version numbers are listed, so all releases lacking a vendor fix may be vulnerable. The flaw enables user‑mode GPU command execution.
Risk and Exploitability
The CVSS score of 7.8 marks this vulnerability as high severity. The EPSS score of less than 1 % indicates a very low but non‑zero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is local, requiring the attacker to be a non‑privileged user who can submit GPU commands that trigger the use‑after‑free. Because exploitation requires only local user privileges and the flaw exploits incomplete driver cleanup, the risk remains high from a severity standpoint but mitigated by the low exploitation likelihood and absent public exploits.
OpenCVE Enrichment