VYPR
Vendor

Imagination Technologies

Products
12
CVEs
54
Across products
87
Status
Private

Products

12

Recent CVEs

54
View all 54 CVEs →
  • CVE-2026-16280CriJul 24, 2026
    risk 0.64cvss 9.8epss 0.00

    An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical…

  • CVE-2025-13952CriJan 24, 2026
    risk 0.64cvss 9.8epss 0.00

    A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a write use-after-free crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further…

  • CVE-2025-6573CriAug 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE).

  • CVE-2026-21732CriMar 20, 2026
    risk 0.62cvss 9.6epss 0.00

    A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits…

  • CVE-2025-25176CriJan 13, 2026
    risk 0.59cvss 9.1epss 0.00

    Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

  • CVE-2025-58411HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused…

  • CVE-2026-22166HigMay 1, 2026
    risk 0.53cvss 8.1epss 0.00

    A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable…

  • CVE-2026-22165HigMay 1, 2026
    risk 0.53cvss 8.1epss 0.00

    A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable further…

  • CVE-2025-0467HigApr 18, 2025
    risk 0.53cvss 8.2epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2026-45198HigAug 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich…

  • CVE-2026-49745HigJul 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds…

  • CVE-2026-49744HigJul 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation…

  • CVE-2026-49743HigJul 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference…

  • CVE-2026-7639HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code…

  • CVE-2026-45203HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in memory after…

  • CVE-2026-45196HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.

  • CVE-2026-41154HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.

  • CVE-2026-34196HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow and map two GPU virtual addresses to the same physical address. One of these virutal mappings can be freed along with the physical page, allowing for a…

  • CVE-2026-22167HigMay 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in…

  • CVE-2026-22163HigMar 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The product utilises a shared resource in a concurrent manner…