Imagination Technologies GPU DDK
cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*
- <= 24.3 RTM
A use-after-free vulnerability has been identified in the GPU driver from Imagination Technologies. This issue arises when software, running as a non-privileged user, makes improper GPU system calls. These calls can trigger use-after-free exceptions in the kernel, leading to potential memory corruption or exploitation.
Exploitation of this vulnerability causes use-after-free exceptions in the kernel, which can lead to memory corruption.
The vulnerability can be reproduced by running software that makes improper GPU system calls while the GPU driver is active. This can be done by creating a program that interacts with the GPU in a way that bypasses normal memory management, such as by manipulating reservation objects or using certain IOCTL calls that the driver does not properly validate.
The DDK kernel module has been updated to address this vulnerability by correcting the improper use of GPU system calls that allowed the exploitation to occur.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.