Skip to main content

Vendor/product archive

imaginationtech / ddk CVEs

Beta · best-effort

24 CVEs tagged to imaginationtech / ddk3 Critical, 13 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-45195

Published Jun 26, 2026

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for t…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21734

Published Jun 26, 2026

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On c…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22167

Published May 1, 2026

Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22166

Published May 1, 2026

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platf…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22165

Published May 1, 2026

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain pla…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-22163

Published Mar 20, 2026

Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes t…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21732

Published Mar 20, 2026

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On c…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21736

Published Mar 9, 2026

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improp…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-13952

Published Jan 24, 2026

A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-10865

Published Jan 13, 2026

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improp…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-58411

Published Jan 13, 2026

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after fre…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58409

Published Jan 13, 2026

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstanc…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-25176

Published Jan 13, 2026

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-58408

Published Dec 1, 2025

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-fre…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58407

Published Nov 17, 2025

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58410

Published Nov 17, 2025

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by imp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46711

Published Sep 22, 2025

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer dereference kernel exceptions.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46709

Published Aug 9, 2025

Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-25179

Published Jun 2, 2025

Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0467

Published Apr 18, 2025

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1