Imagination Technologies GPU Driver Kernel Memory Corruption Vulnerability

Vulnerability

A vulnerability exists in the Imagination Technologies GPU driver that allows software running as a non-privileged user to make improper system calls to the GPU. This can lead to corruption of the kernel's system memory. The issue is present in the GPU DDK releases up to and including 24.3.

Impact

Exploitation of this vulnerability causes corruption of the kernel's system memory, which can lead to system instability and crashes.

Reproduction

The vulnerability can be reproduced by running software that makes improper GPU system calls from a non-privileged user account. This can be done by creating a program that interacts with the GPU driver in a way that bypasses normal memory management safeguards, such as using the DevmemIntChangeSparse remap mode to access freed memory or exploiting integer overflow vulnerabilities to create out-of-bounds memory writes.

Remediation

Users can update to the latest version of the Imagination Technologies GPU driver, which includes patches for this vulnerability. Instructions for updating the driver can be found on the Imagination Technologies website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.6
remediation
7.7
relevance
0.0
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.