CVE-2026-16280: Imaginationtech Ddk
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
Affected products
- Imaginationtech Ddk: before 26.1 (fixed in 26.1); version 26.1 only
Published 2026-07-24. Last modified 2026-08-12.