37 of 38 records publish a fixed version. The other 1 do not, in held sources.
No record in this batch is listed by CISA in held sources.
18 of 38 records name something of its own. For the other 20, held sources say the same thing about each.
Most commonly mapped weakness across the batch: CWE-416: Use After Free.
What this page does not cover
This batch is 38 of the 86 records that cite the same advisory. The other 48 are different findings announced alongside it.
None of those 48 is grouped with any other. Each one has its own record page and nothing else.
The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.
Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.
CVE-2024-12576GPU DDK - Untrusted app can crash firmware by forcing MCU access to non-aligned addressCWE-822 CWE - CWE-822: Untrusted Pointer…
CVE-2024-12837GPU DDK - Exploitable kernel double free on apsFenceSyncCheckpoints allocated with arbitrary sizeCWE-416: Use After Free
CVE-2024-43703GPU DDK - Duplicate calls to RGXCreateFreeList on the same reservation leads to GPU UAFCWE-416 CWE - CWE-416: Use After Free (4.16)
CVE-2024-43704GPU DDK - PowerVR: PVRSRVAcquireProcessHandleBase can cause psProcessHandleBase reuse when PIDs are reusedCWE-668 Exposure of Resource to Wrong Sphere
CVE-2024-46973Exploitable kernel use-after-free on psServerMMUContext due to reference count mismanagementCWE-416: Use After Free
CVE-2024-47891GPU DDK - Exploitable double free on PTL_STREAM_DESC object in the kernel function TLServerCloseStreamKM due to a race…CWE-416: Use After Free
CVE-2024-47898GPU DDK - PVRSRVDeviceSyncOpen use-after-free conditionCWE-416: Use After Free
CVE-2024-47899GPU DDK - PVRSRVDeviceServicesOpen use-after-free conditionCWE-416: Use After Free
CVE-2024-47900GPU DDK - Multiple integer overflow in DmaTransfer PMR_DevPhysAddr functions leading to OOB writesCWE-823: Use of Out-of-range Pointer Offset
CVE-2025-0468GPU DDK - ui64RobustnessAddress can overwrite Freelist / HWRT (and bypass PMMETA)CWE-280: Improper Handling of Insufficient…
CVE-2025-0478GPU DDK - PMMETA_PROTECT PMR can be exported as dma-buf file / GEM objectCWE-280: Improper Handling of Insufficient…
CVE-2025-0835GPU DDK - _WrapExtMemReleasePages called twice if _FlushUMVirtualRange failsCWE-416: Use After Free
CVE-2025-10865GPU DDK - DevmemIntGetReservationData does not ref the PMR it returnsCWE-416: Use After Free
CVE-2025-1706GPU DDK - Improper locking when accessing the pvr_exp_fence objectCWE-416: Use After Free
CVE-2025-25177GPU DDK - Roll-back of pvr_exp_fence not in finalised state can cause UAFCWE-416 CWE - CWE-416: Use After Free (4.17)
CVE-2025-25179GPU DDK - Freelist GPU VA can be remapped to another reservation/PMR to trigger GPU arbitrary write to physical memoryCWE-280: Improper Handling of Insufficient…
CVE-2025-25180GPU DDK - Insufficient validation in RGXCREATEFREELIST creates corrupt freelistCWE-823 CWE - CWE-823: Use of Out-of-range…
CVE-2025-46711GPU DDK - NULL Pointer dereference occurs in LockHandle on bridge entry when connection misusedCWE-476: NULL Pointer Dereference
CVE-2025-58408GPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling codeCWE-416 CWE - CWE-416: Use After Free (4.18)
CVE-2025-58409GPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical memory writes…CWE-119 CWE - CWE-119: Improper Restriction of…
CVE-2025-58410GPU DDK - Multiple calls into PhysmemGEMPrimeExport can inherit write access permission for an existing read-only…CWE-280 CWE - CWE-280: Improper Handling of…
CVE-2025-58411GPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAFCWE-416: Use After Free
CVE-2026-21733GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g.…CWE-280: Improper Handling of Insufficient…
CVE-2026-21736GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabledCWE-280: Improper Handling of Insufficient…
CVE-2026-22167GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memoryCWE-119 CWE - CWE-119: Improper Restriction of…
CVE-2026-34192GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entriesCWE-416: Use After Free (4.15)
CVE-2026-34194GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of…CWE-468: Incorrect Pointer Scaling
CVE-2026-34196GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMemCWE-416: Use After Free
CVE-2026-41156GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding referenceCWE-416: Use After Free (4.15)
CVE-2026-45201GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read and/or write of arbitrary…CWE-1284: Improper Validation of Specified…
CVE-2026-45204GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer…CWE-476 CWE - CWE-476: NULL Pointer Dereference…
CVE-2026-49743GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closedCWE-416: Use After Free (4.20)
CVE-2026-49746GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMemCWE-823 CWE - CWE-823: Use of Out-of-range…
38 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.