VYPR
High severity7.5NVD Advisory· Published Jun 8, 2026· Updated Jun 8, 2026

CVE-2026-22164

CVE-2026-22164

Description

Imagination GPU DDK driver allows non-privileged users to corrupt kernel memory via improper system calls, leading to potential use-after-free vulnerabilities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Imagination GPU DDK driver allows non-privileged users to corrupt kernel memory via improper system calls, leading to potential use-after-free vulnerabilities.

Vulnerability

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. This vulnerability, identified as CVE-2025-58411, affects DDK Releases up to and including 25.2 RTM [1]. The issue arises from mismanagement of resource reference counting, potentially creating a use-after-free scenario [1].

Exploitation

An attacker needs to run software as a non-privileged user. By creating resources of certain types and presenting a set of parameters to the affected interface, the exploit can be used to corrupt kernel memory. This involves causing mismanagement of reference counting, leading to a use-after-free scenario [1].

Impact

Successful exploitation allows an attacker to corrupt kernel memory, potentially leading to a use-after-free condition. This could result in denial-of-service or, in some scenarios, arbitrary code execution within the kernel context.

Mitigation

The DDK kernel module has been updated to address this improper use of GPU system calls to ensure that resources cannot prematurely free whilst references exist. DDK Releases up to and including 25.2 RTM are affected. A resolution is available in updated DDK releases [1].

AI Insight generated on Jun 8, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.