CVE-2026-41154
HIGHGPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse
Title source: cnaDescription
Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.
References (1)
Core 1
Core References
Scores
CVSS v3
7.8
EPSS
0.0013
EPSS Percentile
3.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (6)
Imagination Technologies/Graphics DDK
1.18 RTM2
Imagination Technologies/Graphics DDK
23.2 RTM2
Imagination Technologies/Graphics DDK
24.2 RTM2
Imagination Technologies/Graphics DDK
25.1 RTM2 - 25.3 RTM
Imagination Technologies/Graphics DDK
26.1 RTM1
Imagination Technologies/Graphics DDK
26.1 RTM2
Published
Jul 10, 2026
Tracked Since
Jul 11, 2026