Improper GPU System Calls in Graphics Driver by Imagination Technologies
CVE-2026-22167

7.8HIGH

Key Information:

Vendor
CVE Published:
1 May 2026

What is CVE-2026-22167?

A flaw exists within the Imagination Technologies Graphics Driver that allows a non-privileged user to exploit improper GPU system calls. This could force the GPU to write to arbitrary physical memory pages, leading to the potential corruption of data pages not allocated by the GPU driver. In particular, this exploit targets memory pages in use by the kernel and other drivers, ultimately compromising their functionality. The manipulation of restricted internal GPU buffers can induce secondary effects, potentially resulting in significant system instability and integrity risks.

Affected Version(s)

Graphics DDK Linux 1.18 RTM

Graphics DDK Linux 23.2 RTM

Graphics DDK Linux 24.1 RTM <= 24.2 RTM

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.