CVE-2026-41154
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls.
When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.
Affected (2)
Products: Imaginationtech: Ddk
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 26.1 |
| Running on/with | Platform Versions |
|---|---|
Google Android | All versions |
Linux Linux Kernel | All versions |
References (1)
Source: 367425dc-4d06-4041-9650-c2dc6aaa27ce
Vendor Advisory
Timeline
No history available yet.