Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Graphics DDK — Vulnerabilities & Security Advisories 82

All 82 CVE vulnerabilities found in Graphics DDK, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumeration (CWE) vulnerabilities associated with the Graphics DDK product from its vendor. It serves as a centralized reference for security professionals and developers seeking to understand the historical security landscape of this specific graphics development kit. The aggregation collects data on a wide range of weakness classes, including buffer overflows, improper input validation, memory corruption issues, and privilege escalation flaws. The dataset spans multiple years, capturing all known disclosed vulnerabilities from the product’s initial release to the most recent updates. By reviewing this comprehensive list, users can effectively track the vendor’s security advisories over time to understand their patching cadence and response reliability. Furthermore, this resource allows researchers to analyze specific weakness classes within the context of graphics software development, identifying patterns in code errors or architectural limitations. Users can also look up the full vulnerability history of the Graphics DDK to assess its overall security posture and compliance status. This information is critical for conducting risk assessments, planning security updates, and ensuring that applications built with this SDK meet organizational security standards. The data is organized to facilitate easy searching and filtering by vulnerability type, release version, or discovery date.

Vendor: Imagination Technologies

CVE IDTitleCVSSSeverityPublished
CVE-2026-49746 GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem CWE-823--2026-08-07
CVE-2026-45204 GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory CWE-476--2026-08-07
CVE-2026-45198 GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted CWE-822--2026-08-07
CVE-2026-16280 GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset CWE-190--2026-07-24
CVE-2026-49745 GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 CWE-823--2026-07-24
CVE-2026-49744 GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() CWE-823--2026-07-24
CVE-2026-49743 GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed CWE-416--2026-07-24
CVE-2026-45203 GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU CWE-367--2026-07-10
CVE-2026-45196 GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel CWE-280--2026-07-10
CVE-2026-7639 GPU DDK - Page UAF read in PMMETA_PROTECT heap memory CWE-459--2026-07-10
CVE-2026-41154 GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse CWE-787--2026-07-10
CVE-2026-34196 GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem CWE-416--2026-07-10
CVE-2026-45195 GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted CWE-280--2026-06-26
CVE-2026-21734 GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation CWE-823--2026-06-26
CVE-2026-41156 GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference CWE-416--2026-06-19
CVE-2026-34192 GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries CWE-416--2026-06-19
CVE-2026-41158 GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrink CWE-416--2026-06-12
CVE-2026-41157 GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D CWE-787--2026-06-12
CVE-2026-41155 GPU DDK - SharedSecMem mapped into all GPU virtual address spaces CWE-653--2026-06-12
CVE-2026-34195 GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexes CWE-787--2026-06-12
CVE-2026-34194 GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count CWE-468--2026-06-08
CVE-2026-22164 GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical CWE-122--2026-06-08
CVE-2026-34193 GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr() CWE-823--2026-06-01
CVE-2026-22166 GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable CWE-416 8.8 -2026-05-01
CVE-2026-22165 GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBs CWE-416 8.8 -2026-05-01
CVE-2026-22167 GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory CWE-119 7.8 -2026-05-01
CVE-2026-21733 GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so) CWE-280 7.1AIHighAI2026-04-17
CVE-2026-22163 GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU CWE-820 8.4 -2026-03-20
CVE-2026-21732 GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation CWE-823 8.1 -2026-03-20
CVE-2026-21736 GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled CWE-280 7.1AIHighAI2026-03-09

All 82 known CVE vulnerabilities affecting Graphics DDK with full Chinese analysis, references, and POCs where available.