GPU System Call Vulnerability in Imagination Technologies Driver
CVE-2026-41158
7.8HIGH
What is CVE-2026-41158?
A vulnerability exists in the GPU driver by Imagination Technologies, where software operating as a non-privileged user can invoke GPU system calls to write to memory pages that have been freed. This occurs when physical memory is allocated and subsequently freed without the implementation of a deferred free mechanism. The result is that previously released resources can be manipulated by the GPU, potentially leading to unauthorized access or manipulation of memory, posing significant security risks.
Affected Version(s)
Graphics DDK Linux 25.1 RTM <= 25.3 RTM
Graphics DDK Linux 26.1 RTM
Graphics DDK Linux 1.18 RTM
