CVE-2026-45200: Imagination Technologies Graphics Ddk

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption. Scenario caused by fabricating a specific combination of flags on the allocation interface that would cause an incorrect double free event when freed.

Affected products

  • Imagination Technologies Graphics Ddk: version 24.2 RTM2 only; from 25.1 RTM2, up to and including 25.3 RTM; version 26.1 RTM1 only

Published 2026-09-04. Last modified 2026-09-09.