Requires malware code to misuse the DDK kernel module IOCTL interface.
Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages.
The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.
References
| Link | Resource |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Apr 2026, 16:53
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.imaginationtech.com/gpu-driver-vulnerabilities/ - Vendor Advisory | |
| Summary |
|
|
| First Time |
Imaginationtech ddk
Imaginationtech |
|
| CPE | cpe:2.3:a:imaginationtech:ddk:24.2:*:*:*:*:*:*:* cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:* cpe:2.3:a:imaginationtech:ddk:1.18:*:*:*:*:*:*:* cpe:2.3:a:imaginationtech:ddk:23.2:*:*:*:*:*:*:* cpe:2.3:a:imaginationtech:ddk:1.17:*:*:*:*:*:*:* cpe:2.3:a:imaginationtech:ddk:24.1:*:*:*:*:*:*:* |
23 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
20 Mar 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-20 23:16
Updated : 2026-04-21 16:53
NVD link : CVE-2026-22163
Mitre link : CVE-2026-22163
CVE.ORG link : CVE-2026-22163
JSON object : View
Products Affected
imaginationtech
- ddk
CWE
CWE-820
Missing Synchronization
