CVE-2026-49746
Deferred
Deferred - Pending Action
BaseFortify
Vulnerability report for CVE-2026-49746, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-07
Last updated on: 2026-09-03
Assigner: imaginationtech
Description
Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages.
Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Imagination | Technologies | Graphics DDK 1.18 RTM2 |
| Imagination | Technologies | Graphics DDK 23.2 RTM2 |
| Imagination | Technologies | Graphics DDK 24.2 RTM2 |
| Imagination | Technologies | Graphics DDK 25.1 RTM2 |
| Imagination | Technologies | Graphics DDK 26.1 RTM1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-823 | The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer. |