GPU System Call Vulnerability in Imagination Technologies Driver
CVE-2026-41158

7.8HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-41158?

A vulnerability exists in the GPU driver by Imagination Technologies, where software operating as a non-privileged user can invoke GPU system calls to write to memory pages that have been freed. This occurs when physical memory is allocated and subsequently freed without the implementation of a deferred free mechanism. The result is that previously released resources can be manipulated by the GPU, potentially leading to unauthorized access or manipulation of memory, posing significant security risks.

Affected Version(s)

Graphics DDK Linux 25.1 RTM <= 25.3 RTM

Graphics DDK Linux 26.1 RTM

Graphics DDK Linux 1.18 RTM

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.