Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.
This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ |
|
Sun, 03 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Imaginationtech
Imaginationtech graphics Ddk |
|
| Vendors & Products |
Imaginationtech
Imaginationtech graphics Ddk |
Fri, 01 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 01 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory. | |
| Title | GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory | |
| Weaknesses | CWE-119 | |
| References |
|
Status: PUBLISHED
Assigner: imaginationtech
Published:
Updated: 2026-05-01T19:16:56.328Z
Reserved: 2026-01-06T15:50:36.205Z
Link: CVE-2026-22167
Updated: 2026-05-01T19:10:46.956Z
Status : Awaiting Analysis
Published: 2026-05-01T16:16:29.693
Modified: 2026-05-06T19:05:56.337
Link: CVE-2026-22167
No data.
OpenCVE Enrichment
Updated: 2026-05-03T21:30:27Z