Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Graphics DDK — Vulnerabilities & Security Advisories 82

All 82 CVE vulnerabilities found in Graphics DDK, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities for the Graphics Driver Development Kit (DDK) categorized under software weaknesses. It collects data on common flaws such as buffer overflows, race conditions, and memory corruption issues that may affect driver stability and system security. The repository covers vulnerability reports from 2015 to the present, providing a historical view of how these issues have evolved. Users can utilize this resource to track vendor advisories and monitor public disclosures related to the Graphics DDK. The platform allows developers to understand specific weakness classes and their impact on graphics processing systems. It also enables teams to look up a product’s vulnerability history to assess risk exposure over time. This information supports proactive security management by highlighting recurring patterns in driver development flaws. By centralizing this data, the page simplifies the process of identifying potential threats in legacy and current codebases. Engineers can compare current implementations against past incidents to prevent similar exploits. The aggregation serves as a reference for compliance audits and security reviews. It helps stakeholders evaluate the maturity of their graphics stack against industry benchmarks. Access to this consolidated view aids in prioritizing patches and updates based on severity and frequency. The data is sourced from reputable vulnerability databases and vendor announcements. This ensures accuracy and relevance for technical audiences. Developers seeking to harden their graphics applications will find this page essential for maintaining robust security practices. The focus remains on factual reporting to assist in informed decision-making regarding software lifecycle management.

Vendor: Imagination Technologies

CVE IDTitleCVSSSeverityPublished
CVE-2026-49746 GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem CWE-823--2026-08-07
CVE-2026-45204 GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory CWE-476--2026-08-07
CVE-2026-45198 GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted CWE-822--2026-08-07
CVE-2026-16280 GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset CWE-190--2026-07-24
CVE-2026-49745 GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 CWE-823--2026-07-24
CVE-2026-49744 GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() CWE-823--2026-07-24
CVE-2026-49743 GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed CWE-416--2026-07-24
CVE-2026-45203 GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU CWE-367--2026-07-10
CVE-2026-45196 GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel CWE-280--2026-07-10
CVE-2026-7639 GPU DDK - Page UAF read in PMMETA_PROTECT heap memory CWE-459--2026-07-10
CVE-2026-41154 GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse CWE-787--2026-07-10
CVE-2026-34196 GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem CWE-416--2026-07-10
CVE-2026-45195 GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted CWE-280--2026-06-26
CVE-2026-21734 GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation CWE-823--2026-06-26
CVE-2026-41156 GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference CWE-416--2026-06-19
CVE-2026-34192 GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries CWE-416--2026-06-19
CVE-2026-41158 GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrink CWE-416--2026-06-12
CVE-2026-41157 GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D CWE-787--2026-06-12
CVE-2026-41155 GPU DDK - SharedSecMem mapped into all GPU virtual address spaces CWE-653--2026-06-12
CVE-2026-34195 GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexes CWE-787--2026-06-12
CVE-2026-34194 GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count CWE-468--2026-06-08
CVE-2026-22164 GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical CWE-122--2026-06-08
CVE-2026-34193 GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr() CWE-823--2026-06-01
CVE-2026-22166 GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable CWE-416 8.8 -2026-05-01
CVE-2026-22165 GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBs CWE-416 8.8 -2026-05-01
CVE-2026-22167 GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory CWE-119 7.8 -2026-05-01
CVE-2026-21733 GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so) CWE-280 7.1AIHighAI2026-04-17
CVE-2026-22163 GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU CWE-820 8.4 -2026-03-20
CVE-2026-21732 GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation CWE-823 8.1 -2026-03-20
CVE-2026-21736 GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled CWE-280 7.1AIHighAI2026-03-09

All 82 known CVE vulnerabilities affecting Graphics DDK with full Chinese analysis, references, and POCs where available.