VYPR

GPU DDK

by Imagination Technologies

CVEs (10)

  • CVE-2026-16280Jul 24, 2026
    risk 0.00cvss epss 0.00

    An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical…

  • CVE-2026-49745Jul 24, 2026
    risk 0.00cvss epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds…

  • CVE-2026-49744Jul 24, 2026
    risk 0.00cvss epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation…

  • CVE-2026-49743Jul 24, 2026
    risk 0.00cvss epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference…

  • CVE-2026-45196Jul 10, 2026
    risk 0.00cvss epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.

  • CVE-2026-7639Jul 10, 2026
    risk 0.00cvss epss 0.00

    Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code…

  • CVE-2026-41154Jul 10, 2026
    risk 0.00cvss epss 0.00

    Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.

  • CVE-2026-34196Jul 10, 2026
    risk 0.00cvss epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow and map two GPU virtual addresses to the same physical address. One of these virutal mappings can be freed along with the physical page, allowing for a…

  • CVE-2026-45195Jun 26, 2026
    risk 0.00cvss epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel. Addresses passed to the GPU Firmware can be used by the Firmware for more…

  • CVE-2026-21734Jun 26, 2026
    risk 0.00cvss epss 0.00

    A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits…