CVE-2026-41157 Details
Description
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound write in the GPU user-space driver, leading to memory corruption and possible browser/GPU process crash. The software computes a required memory size from untrusted input, but integer overflow can produce a value smaller than needed. Subsequent write operations may then occur past the intended memory boundary, corrupting adjacent memory and causing process instability or termination.
A vulnerability exists in the Imagination Technologies GPU driver development kit (DDK) version 25.2 RTM and prior, allowing for an out-of-bounds write in the GPU user-space driver. This issue arises when a web page with unusual WebGPU content is loaded into the GPU GLES render process. The vulnerability is caused by the software calculating required memory sizes from untrusted input, leading to an integer overflow. This overflow can create a memory size value smaller than needed, causing write operations to extend beyond the intended memory boundary. The result is memory corruption, which can crash the browser or the GPU process.
Users can update to the latest version of the Imagination Technologies GPU driver development kit (DDK) to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | BundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| Imagination Technologies GPU DDK | <= 26.1 RTM1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | imaginationtech |
Volerion