Memory Corruption Vulnerability in GPU Rendering Process by Imagination Technologies
CVE-2026-41157
9.8CRITICAL
What is CVE-2026-41157?
A vulnerability exists in the GPU user-space driver from Imagination Technologies that allows an out-of-bound write triggered by a web page with unusual WebGPU content. This flaw arises from the software incorrectly calculating the required memory size based on untrusted input, which can lead to an integer overflow. As a result, the allocated memory may be insufficient for operations, leading to data being written beyond allocated boundaries and corrupting adjacent memory. This instability can cause the browser or GPU processes to crash, posing significant risks to system integrity and user experience.
Affected Version(s)
Graphics DDK Linux 1.18 RTM
Graphics DDK Linux 23.2 RTM
Graphics DDK Linux 24.2 RTM
