๐Ÿ” CVE Alert

CVE-2026-41156

UNKNOWN 0.0

GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources creating a write use after free scenario. A shared resource (memory page) managed by a CPU thread of control (driver) and accessed by a GPU thread of control (Firmware) can cause a write UAF when the CPU thread frees the resource before the GPU FW has finished accessing it.

CWE CWE-416
Vendor imagination technologies
Product graphics ddk
Published Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for imagination technologies graphics ddk

Be the first to know when new unknown vulnerabilities affecting imagination technologies graphics ddk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Imagination Technologies / Graphics DDK
1.18 RTM 23.2 RTM 24.2 RTM 25.1 RTM โ‰ค 25.3 RTM 26.1 RTM

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
imaginationtech.com: https://www.imaginationtech.com/gpu-driver-vulnerabilities/