CVE-2026-22163

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/03/2026
Last modified:
21/04/2026

Description

Requires malware code to misuse the DDK kernel module IOCTL interface.<br /> <br /> Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages.<br /> <br /> The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:* 25.1 (including) 25.3 (including)
cpe:2.3:a:imaginationtech:ddk:1.17:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:1.18:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:23.2:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:24.1:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:24.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools