CVE-2026-41158: Imagination Technologies Graphics Ddk
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.
Affected products
- Imagination Technologies Graphics Ddk: from 25.1 RTM, up to and including 25.3 RTM; version 26.1 RTM only
Published 2026-06-12. Last modified 2026-06-17.