Description
Requires malware code to misuse the DDK kernel module IOCTL interface.

Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages.

The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.
Published: 2026-03-20
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution through arbitrary physical memory writes via DDK IOCTL misuse
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Apr 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech ddk
CPEs cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:1.17:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:1.18:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:23.2:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:24.1:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:24.2:*:*:*:*:*:*:*
Vendors & Products Imaginationtech ddk

Mon, 23 Mar 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech graphics Ddk
Vendors & Products Imaginationtech
Imaginationtech graphics Ddk

Fri, 20 Mar 2026 23:00:00 +0000

Type Values Removed Values Added
Description Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.
Title GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU
Weaknesses CWE-820
References

Subscriptions

Imaginationtech Ddk Graphics Ddk
cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published:

Updated: 2026-03-23T14:59:27.041Z

Reserved: 2026-01-06T15:50:36.204Z

Link: CVE-2026-22163

cve-icon Vulnrichment

Updated: 2026-03-23T14:56:10.816Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-20T23:16:42.640

Modified: 2026-04-21T16:53:35.500

Link: CVE-2026-22163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:34:01Z

Weaknesses