CVE-2026-7639: Imaginationtech Ddk
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code could lead to incomplete cleanup of an internal driver state, allowing for future unauthorized access to the contents of the physical memory.
Affected products
- Imaginationtech Ddk: before 26.1 (fixed in 26.1); version 26.1 only
Published 2026-07-10. Last modified 2026-08-12.