vciy

CVEs we hold for Imagination

Records whose assigning authority named Imagination as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-7639GPU DDK - Page UAF read in PMMETA_PROTECT heap memoryImagination Technologies Graphics DDK
CVE-2026-49746GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMemImagination Technologies Graphics DDK
CVE-2026-49745GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0Imagination Technologies Graphics DDK
CVE-2026-49744GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()Imagination Technologies Graphics DDK
CVE-2026-49743GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closedImagination Technologies Graphics DDK
CVE-2026-45204GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer…Imagination Technologies Graphics DDK
CVE-2026-45203GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOUImagination Technologies Graphics DDK
CVE-2026-45202GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`Imagination Technologies Graphics DDK
CVE-2026-45201GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read and/or write of arbitrary…Imagination Technologies Graphics DDK
CVE-2026-45200GPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by _EncodeAllocationFlagsImagination Technologies Graphics DDK
CVE-2026-45199GPU DDK - rgxfw_to_ptr() does not reject FW private data pointersImagination Technologies Graphics DDK
CVE-2026-45198GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrustedImagination Technologies Graphics DDK
CVE-2026-45197GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSetImagination Technologies Graphics DDK
CVE-2026-45196GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernelImagination Technologies Graphics DDK
CVE-2026-45195GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrustedImagination Technologies Graphics DDK
CVE-2026-41158GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrinkImagination Technologies Graphics DDK
CVE-2026-41157GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3DImagination Technologies Graphics DDK
CVE-2026-41156GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding referenceImagination Technologies Graphics DDK
CVE-2026-41155GPU DDK - SharedSecMem mapped into all GPU virtual address spacesImagination Technologies Graphics DDK
CVE-2026-41154GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_SparseImagination Technologies Graphics DDK
CVE-2026-34196GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMemImagination Technologies Graphics DDK
CVE-2026-34195GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page…Imagination Technologies Graphics DDK
CVE-2026-34194GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of…Imagination Technologies Graphics DDK
CVE-2026-34193GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()Imagination Technologies Graphics DDK
CVE-2026-34192GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entriesImagination Technologies Graphics DDK
CVE-2026-22167GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memoryImagination Technologies Graphics DDK
CVE-2026-22166GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachableImagination Technologies Graphics DDK
CVE-2026-22165GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBsImagination Technologies Graphics DDK
CVE-2026-22164GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogicalImagination Technologies Graphics DDK
CVE-2026-22163GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPUImagination Technologies Graphics DDK
CVE-2026-21736GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabledImagination Technologies Graphics DDK
CVE-2026-21734GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilationImagination Technologies Graphics DDK
CVE-2026-21733GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g.…Imagination Technologies Graphics DDK
CVE-2026-21732GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilationImagination Technologies Graphics DDK
CVE-2026-16280GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffsetImagination Technologies Graphics DDK
CVE-2025-8109GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operationImagination Technologies Graphics DDK
CVE-2025-6573GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/OverwriteImagination Technologies Graphics DDK
CVE-2025-58411GPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAFImagination Technologies Graphics DDK
CVE-2025-58410GPU DDK - Multiple calls into PhysmemGEMPrimeExport can inherit write access permission for an existing read-only…Imagination Technologies Graphics DDK
CVE-2025-58409GPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical memory writes…Imagination Technologies Graphics DDK
CVE-2025-58408GPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling codeImagination Technologies Graphics DDK
CVE-2025-58407GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSetImagination Technologies Graphics DDK
CVE-2025-46711GPU DDK - NULL Pointer dereference occurs in LockHandle on bridge entry when connection misusedImagination Technologies Graphics DDK
CVE-2025-46710no title heldImagination Technologies Graphics DDK
CVE-2025-46709GPU DDK - Security fix for PP-171570 can lead to an uninitialised pointer dereference and memory leakImagination Technologies Graphics DDK
CVE-2025-46708GPU DDK - Guest VM can delay the FW and GPU from processing workloads from other VMsImagination Technologies Graphics DDK
CVE-2025-46707GPU DDK - Guest VM can override its own FW VZ connection state after the FW has close itImagination Technologies Graphics DDK
CVE-2025-25180GPU DDK - Insufficient validation in RGXCREATEFREELIST creates corrupt freelistImagination Technologies Graphics DDK
CVE-2025-25179GPU DDK - Freelist GPU VA can be remapped to another reservation/PMR to trigger GPU arbitrary write to physical memoryImagination Technologies Graphics DDK
CVE-2025-25178GPU DDK - PhysmemWrapExtMem uiSize=0 corrupts kernel memoryImagination Technologies Graphics DDK
CVE-2025-25177GPU DDK - Roll-back of pvr_exp_fence not in finalised state can cause UAFImagination Technologies Graphics DDK
CVE-2025-25176GPU DDK - GPU Register value contents leaked from secure workloads to non-secure worldImagination Technologies Graphics DDK
CVE-2025-1706GPU DDK - Improper locking when accessing the pvr_exp_fence objectImagination Technologies Graphics DDK
CVE-2025-13952GPU DDK - libusc UAF via WebGPU shaders at MergeConsecutiveBarriersBPImagination Technologies Graphics DDK
CVE-2025-10865GPU DDK - DevmemIntGetReservationData does not ref the PMR it returnsImagination Technologies Graphics DDK
CVE-2025-0835GPU DDK - _WrapExtMemReleasePages called twice if _FlushUMVirtualRange failsImagination Technologies Graphics DDK
CVE-2025-0478GPU DDK - PMMETA_PROTECT PMR can be exported as dma-buf file / GEM objectImagination Technologies Graphics DDK
CVE-2025-0468GPU DDK - ui64RobustnessAddress can overwrite Freelist / HWRT (and bypass PMMETA)Imagination Technologies Graphics DDK
CVE-2025-0467GPU DDK - rgxfw_hwperf_get_packet_buffer OOB writeImagination Technologies Graphics DDK
CVE-2024-52939GPU DDK - RGXFWIF_HWPERF_CTL_BLK.uiNumCounters OOB writeImagination Technologies Graphics DDK
CVE-2024-52938GPU DDK - rgxfw_pm_add_freelist_for_reconstruction OOB writeImagination Technologies Graphics DDK
CVE-2024-52937GPU DDK - rgxfw_kernel_CMD_DISABLE_ZSSTORE OOB write via ui32WriteOffsetOfDisableZSStoreImagination Technologies Graphics DDK
CVE-2024-52936GPU DDK - rgxfw_hwperf_config OOB read & writeImagination Technologies Graphics DDK
CVE-2024-52935GPU DDK - psContext->eDM gives OOB writeImagination Technologies Graphics DDK
CVE-2024-47900GPU DDK - Multiple integer overflow in DmaTransfer PMR_DevPhysAddr functions leading to OOB writesImagination Technologies Graphics DDK
CVE-2024-47899GPU DDK - PVRSRVDeviceServicesOpen use-after-free conditionImagination Technologies Graphics DDK
CVE-2024-47898GPU DDK - PVRSRVDeviceSyncOpen use-after-free conditionImagination Technologies Graphics DDK
CVE-2024-47897GPU DDK - PVRSRVRGXGetEnabledHWPerfBlocksKM off-by-one OOB writeImagination Technologies Graphics DDK
CVE-2024-47896GPU DDK - rgxfw_hwr_log_info OOB write via psHWRInfoBuf->ui32WriteIndexImagination Technologies Graphics DDK
CVE-2024-47895GPU DDK - OOB read into fwlog due to unchecked block countImagination Technologies Graphics DDK
CVE-2024-47894GPU DDK - Out of bounds read into fwlog due to unchecked loop boundsImagination Technologies Graphics DDK
CVE-2024-47893GPU DDK - OOB read and write of the shared KMD/FW memory heap (VZ/TEE setups)Imagination Technologies Graphics DDK
CVE-2024-47892GPU DDK - UAF of kernel memory in PMRUnlockPhysAddressesOSMem for on-demand non-4KB PMRs in system memory (UMA)Imagination Technologies Graphics DDK
CVE-2024-47891GPU DDK - Exploitable double free on PTL_STREAM_DESC object in the kernel function TLServerCloseStreamKM due to a race…Imagination Technologies Graphics DDK
CVE-2024-46975GPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mappingImagination Technologies Graphics DDK
CVE-2024-46974GPU DDK - Arbitrary write of read-only dmabufImagination Technologies Graphics DDK
CVE-2024-46973Exploitable kernel use-after-free on psServerMMUContext due to reference count mismanagementImagination Technologies Graphics DDK
CVE-2024-46972GPU DDK - Security: Reference count overflow in pvr_sync_rollback_export_fenceImagination Technologies Graphics DDK
CVE-2024-46971GPU DDK - UAF of memory in PMRUnlockSysPhysAddressesLocalMem for on-demand PMRs on PCI (LMA) systemsImagination Technologies Graphics DDK
CVE-2024-43705GPU DDK - Security: Exploitable PVRSRVBridgePhysmemWrapExtMem may lead to overwrite read-only file/memory (e.g. libc.so)Imagination Technologies Graphics DDK
CVE-2024-43704GPU DDK - PowerVR: PVRSRVAcquireProcessHandleBase can cause psProcessHandleBase reuse when PIDs are reusedImagination Technologies Graphics DDK
CVE-2024-43703GPU DDK - Duplicate calls to RGXCreateFreeList on the same reservation leads to GPU UAFImagination Technologies Graphics DDK
CVE-2024-43702GPU DDK - MLIST/PM render state buffers writable allowing arbitrary writes to kernel memory pagesImagination Technologies Graphics DDK
CVE-2024-43701GPU DDK - PowerVR: TLB invalidate UAF of dma_buf imported into multiple GPU devicesImagination Technologies Graphics DDK
CVE-2024-12837GPU DDK - Exploitable kernel double free on apsFenceSyncCheckpoints allocated with arbitrary sizeImagination Technologies Graphics DDK
CVE-2024-12577GPU DDK - rgxfw_pcset_ungrab OOB write via psFWMemContext->uiPageCatBaseRegSetImagination Technologies Graphics DDK
CVE-2024-12576GPU DDK - Untrusted app can crash firmware by forcing MCU access to non-aligned addressImagination Technologies Graphics DDK

87 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.