๐Ÿ” CVE Alert

CVE-2026-49743

UNKNOWN 0.0

GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.

CWE CWE-416
Vendor imagination technologies
Product graphics ddk
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for imagination technologies graphics ddk

Be the first to know when new unknown vulnerabilities affecting imagination technologies graphics ddk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Imagination Technologies / Graphics DDK
24.2 RTM2 25.1 RTM2 โ‰ค 25.3 RTM 26.1 RTM1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
imaginationtech.com: https://www.imaginationtech.com/gpu-driver-vulnerabilities/