CVE-2026-21733: Imaginationtech Ddk
High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files. This is caused by improper handling of GPU memory reservation protections.
Affected products
- Imaginationtech Ddk: before 25.3 (fixed in 25.3); version 25.3 only
Published 2026-04-17. Last modified 2026-08-12.