Memory Corruption Vulnerability in GPU Rendering Process by Imagination Technologies
CVE-2026-41157

9.8CRITICAL

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-41157?

A vulnerability exists in the GPU user-space driver from Imagination Technologies that allows an out-of-bound write triggered by a web page with unusual WebGPU content. This flaw arises from the software incorrectly calculating the required memory size based on untrusted input, which can lead to an integer overflow. As a result, the allocated memory may be insufficient for operations, leading to data being written beyond allocated boundaries and corrupting adjacent memory. This instability can cause the browser or GPU processes to crash, posing significant risks to system integrity and user experience.

Affected Version(s)

Graphics DDK Linux 1.18 RTM

Graphics DDK Linux 23.2 RTM

Graphics DDK Linux 24.2 RTM

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.