CVE-2026-21736
Awaiting Analysis
Awaiting Analysis - Queue
Improper Memory Protection Allows Write Access via GPU Calls
Publication date: 2026-03-09
Last updated on: 2026-03-10
Assigner: imaginationtech
Description
Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory.
This is caused by improper handling of the memoryΒ protectionsΒ for the user-mode wrapped memory resource.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| imaginationtech | ddk | 25.1 |
| imaginationtech | ddk | 25.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-280 | The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. |