Integer Overflow Vulnerability in Imagination Technologies GPU Driver
CVE-2026-16280

9.8CRITICAL

Key Information:

Vendor
CVE Published:
24 July 2026

What is CVE-2026-16280?

An integer overflow vulnerability exists in the calculation of physical offsets for sparse PMRs within the Imagination Technologies GPU driver. This flaw may occur when dealing with PMRs exceeding 4 GB in size, resulting in 32-bit truncation of address computations. Consequently, this can lead to incorrect mappings by the GPU MMU, potentially allowing non-privileged users to access unintended physical memory, thereby risking memory corruption and information disclosure.

Affected Version(s)

Graphics DDK Linux 1.18 RTM2

Graphics DDK Linux 23.2 RTM2

Graphics DDK Linux 24.2 RTM2

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.