CVE-2026-49746 Details
Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages. Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.
A vulnerability exists in the Imagination Technologies GPU driver that allows software running as a non-privileged user to make improper GPU system calls. This can lead to out-of-bounds (OOB) reads of kernel memory and, in some cases, use-after-free (UAF) conditions of arbitrary pages in GPU memory. The issue arises from incorrect validation of array indices, which can be exploited to read beyond allocated memory boundaries and potentially manipulate memory management, causing UAF scenarios.
The DDK kernel module has been updated to address this vulnerability by correcting the validation of array indices and ensuring that resources are properly managed to prevent use-after-free conditions. Users should update to the latest DDK release that includes these fixes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-823 | Use of Out-of-range Pointer Offset | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| Imagination Technologies GPU DDK | <= 25.2 RTM <= 25.1 RTM2 <= 25.3 RTM <= 26.1 RTM1 ~24.2 RTM2 ~24.1 RTM2 ~25.1 RTM1 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | imaginationtech |
Volerion