Imaginationtech
Imaginationtech DDK: vulnerabilidades y CVE
Imaginationtech DDK tiene 35 vulnerabilidades publicadas, 27 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE35
Últimos 12 meses27
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-16280 | Crítica (9.8) | 0.53% | — | 24 jul 2026 | An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a… |
| CVE-2026-49745 | Alta (7.8) | 0.16% | — | 24 jul 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM… |
| CVE-2026-49744 | Alta (7.8) | 0.16% | — | 24 jul 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware… |
| CVE-2026-49743 | Alta (7.8) | 0.16% | — | 24 jul 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission… |
| CVE-2026-7639 | Alta (7.8) | 0.18% | — | 10 jul 2026 | Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering… |
| CVE-2026-45203 | Alta (7.8) | 0.13% | — | 10 jul 2026 | Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a… |
| CVE-2026-45196 | Alta (7.8) | 0.14% | — | 10 jul 2026 | Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation. |
| CVE-2026-41154 | Alta (7.8) | 0.18% | — | 10 jul 2026 | Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation,… |
| CVE-2026-34196 | Alta (7.8) | 0.17% | — | 10 jul 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow and map two GPU virtual addresses to the same physical address. One of these virutal mappings can be… |
| CVE-2026-45195 | Alta (7.8) | 0.14% | — | 26 jun 2026 | Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the… |
| CVE-2026-21734 | Alta (7.7) | 0.16% | — | 26 jun 2026 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler… |
| CVE-2026-34193 | Media (4.3) | 0.22% | — | 1 jun 2026 | Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a… |
| CVE-2026-22167 | Alta (7.8) | 0.15% | — | 1 may 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data… |
| CVE-2026-22166 | Alta (8.1) | 0.39% | — | 1 may 2026 | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing… |
| CVE-2026-22165 | Alta (8.1) | 0.35% | — | 1 may 2026 | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing… |
| CVE-2026-21733 | Alta (7.3) | 0.10% | — | 17 abr 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory… |
| CVE-2026-22163 | Alta (7.8) | 0.08% | — | 20 mar 2026 | Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The… |
| CVE-2026-21732 | Crítica (9.6) | 0.29% | — | 20 mar 2026 | A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler… |
| CVE-2026-21736 | Media (4.4) | 0.12% | — | 9 mar 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for… |
| CVE-2025-13952 | Crítica (9.8) | 0.46% | — | 24 ene 2026 | A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the… |
| CVE-2025-10865 | Alta (7.8) | 0.13% | — | 13 ene 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal… |
| CVE-2025-58411 | Alta (8.8) | 0.17% | — | 13 ene 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management… |
| CVE-2025-58409 | Baja (3.5) | 0.15% | — | 13 ene 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt… |
| CVE-2025-25176 | Crítica (9.1) | 0.35% | — | 13 ene 2026 | Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform. |
| CVE-2025-58408 | Media (5.9) | 0.13% | — | 1 dic 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free. The Use After Free common weakness… |
| CVE-2025-58407 | Alta (7.4) | 0.19% | — | 17 nov 2025 | Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the… |
| CVE-2025-58410 | Alta (7.5) | 0.28% | — | 17 nov 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections… |
| CVE-2025-46711 | Media (5.5) | 0.13% | — | 22 sept 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer dereference kernel exceptions. |
| CVE-2025-46709 | Alta (7.5) | 0.34% | — | 9 ago 2025 | Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception. |
| CVE-2025-46708 | Media (4.3) | 0.19% | — | 27 jun 2025 | Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU. |