CVE-2026-45201: Imagination Technologies Graphics Ddk

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Software installed and run as a non-privileged user may conduct improper GPU system calls to pass invalid log2 page size when allocating physical pages leading to OOB read and/or write due to improper validation of the said value. Such crafted log2 page size could lead to 4K pages being treated as higher order pages and allowing read and/or write access to the memory beyond 4K threshold.

Affected products

  • Imagination Technologies Graphics Ddk: version 24.2 RTM2 only; from 25.1 RTM2, up to and including 25.3 RTM; version 26.1 RTM1 only

Published 2026-08-21. Last modified 2026-09-03.