CVE-2026-41154

HIGH

GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse

Title source: cna
STIX 2.1

Description

Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (6)
Imagination Technologies/Graphics DDK 1.18 RTM2
Imagination Technologies/Graphics DDK 23.2 RTM2
Imagination Technologies/Graphics DDK 24.2 RTM2
Imagination Technologies/Graphics DDK 25.1 RTM2 - 25.3 RTM
Imagination Technologies/Graphics DDK 26.1 RTM1
Imagination Technologies/Graphics DDK 26.1 RTM2
Published Jul 10, 2026
Tracked Since Jul 11, 2026