CVE-2026-22163
Received Received - Intake
Arbitrary Memory Write via GPU IOCTL in DDK Kernel Module

Publication date: 2026-03-20

Last updated on: 2026-04-21

Assigner: imaginationtech

Description
Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-20
Last Modified
2026-04-21
Generated
2026-05-06
AI Q&A
2026-03-21
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 6 associated CPEs
Vendor Product Version / Range
imaginationtech ddk 24.2
imaginationtech ddk From 25.1 (inc) to 25.3 (inc)
imaginationtech ddk 1.17
imaginationtech ddk 1.18
imaginationtech ddk 23.2
imaginationtech ddk 24.1
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-820 The product utilizes a shared resource in a concurrent manner but does not attempt to synchronize access to the resource.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves the misuse of the DDK kernel module IOCTL interface by malware code. The interface can be exploited in an unsupported way that allows the GPU to be subverted to perform writes to arbitrary physical memory pages. Additionally, the product uses a shared resource concurrently without synchronizing access, which contributes to the vulnerability.


How can this vulnerability impact me? :

An attacker exploiting this vulnerability could potentially write to arbitrary physical memory pages via the GPU, which may lead to unauthorized modification of system memory. This can result in system instability, data corruption, privilege escalation, or execution of malicious code.


How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

I don't know


How can this vulnerability be detected on my network or system? Can you suggest some commands?

I don't know


What immediate steps should I take to mitigate this vulnerability?

I don't know


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart