CVE-2026-21736

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imaginationtech:ddk:25.1:-:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:25.1:rtm2:*:*:*:*:*:*

History

10 Mar 2026, 18:46

Type Values Removed Values Added
References () https://www.imaginationtech.com/gpu-driver-vulnerabilities/ - () https://www.imaginationtech.com/gpu-driver-vulnerabilities/ - Vendor Advisory
CPE cpe:2.3:a:imaginationtech:ddk:25.1:-:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:25.1:rtm2:*:*:*:*:*:*
Summary
  • (es) Software instalado y ejecutado como un usuario no privilegiado puede realizar llamadas al sistema de GPU impropias para obtener permiso de escritura a memoria de modo de usuario encapsulada de solo lectura. Esto es causado por el manejo impropio de las protecciones de memoria para el recurso de memoria encapsulada de modo de usuario.
First Time Imaginationtech ddk
Imaginationtech

09 Mar 2026, 17:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.4

09 Mar 2026, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 13:15

Updated : 2026-03-10 18:46


NVD link : CVE-2026-21736

Mitre link : CVE-2026-21736

CVE.ORG link : CVE-2026-21736


JSON object : View

Products Affected

imaginationtech

  • ddk
CWE
CWE-280

Improper Handling of Insufficient Permissions or Privileges