Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Imagination Technologies — Vulnerabilities & Security Advisories 82

Browse all 82 CVE security advisories affecting Imagination Technologies. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Imagination Technologies specializes in graphics processing units and multimedia technologies, primarily supplying intellectual property licenses to semiconductor manufacturers for embedded systems and mobile devices. With fifty-nine recorded Common Vulnerabilities and Exposures, the company’s historical attack surface has predominantly featured remote code execution and buffer overflow flaws within its proprietary middleware and driver software. These vulnerabilities often stem from insufficient input validation in image processing pipelines, allowing attackers to escalate privileges or execute arbitrary code on affected endpoints. While no single catastrophic breach has defined the firm’s public security narrative, the cumulative impact of these CVEs highlights risks in its embedded software stack. Security assessments indicate that many issues were resolved through routine firmware updates, yet the persistent presence of memory corruption bugs suggests ongoing challenges in securing complex, low-level hardware abstractions used across diverse consumer electronics.

Top products by Imagination Technologies: Graphics DDK
CVE IDTitleCVSSSeverityPublished
CVE-2026-49746 GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem — Graphics DDKCWE-823--2026-08-07
CVE-2026-45204 GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory — Graphics DDKCWE-476--2026-08-07
CVE-2026-45198 GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted — Graphics DDKCWE-822--2026-08-07
CVE-2026-16280 GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset — Graphics DDKCWE-190--2026-07-24
CVE-2026-49745 GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 — Graphics DDKCWE-823--2026-07-24
CVE-2026-49744 GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() — Graphics DDKCWE-823--2026-07-24
CVE-2026-49743 GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed — Graphics DDKCWE-416--2026-07-24
CVE-2026-45203 GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU — Graphics DDKCWE-367--2026-07-10
CVE-2026-45196 GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel — Graphics DDKCWE-280--2026-07-10
CVE-2026-7639 GPU DDK - Page UAF read in PMMETA_PROTECT heap memory — Graphics DDKCWE-459--2026-07-10
CVE-2026-41154 GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse — Graphics DDKCWE-787--2026-07-10
CVE-2026-34196 GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem — Graphics DDKCWE-416--2026-07-10
CVE-2026-45195 GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted — Graphics DDKCWE-280--2026-06-26
CVE-2026-21734 GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation — Graphics DDKCWE-823--2026-06-26
CVE-2026-41156 GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference — Graphics DDKCWE-416--2026-06-19
CVE-2026-34192 GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries — Graphics DDKCWE-416--2026-06-19
CVE-2026-41158 GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrink — Graphics DDKCWE-416--2026-06-12
CVE-2026-41157 GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D — Graphics DDKCWE-787--2026-06-12
CVE-2026-41155 GPU DDK - SharedSecMem mapped into all GPU virtual address spaces — Graphics DDKCWE-653--2026-06-12
CVE-2026-34195 GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexes — Graphics DDKCWE-787--2026-06-12
CVE-2026-34194 GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count — Graphics DDKCWE-468--2026-06-08
CVE-2026-22164 GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical — Graphics DDKCWE-122--2026-06-08
CVE-2026-34193 GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr() — Graphics DDKCWE-823--2026-06-01
CVE-2026-22166 GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable — Graphics DDKCWE-416 8.8 -2026-05-01
CVE-2026-22165 GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBs — Graphics DDKCWE-416 8.8 -2026-05-01
CVE-2026-22167 GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory — Graphics DDKCWE-119 7.8 -2026-05-01
CVE-2026-21733 GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so) — Graphics DDKCWE-280 7.1AIHighAI2026-04-17
CVE-2026-22163 GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU — Graphics DDKCWE-820 8.4 -2026-03-20
CVE-2026-21732 GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation — Graphics DDKCWE-823 8.1 -2026-03-20
CVE-2026-21736 GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled — Graphics DDKCWE-280 7.1AIHighAI2026-03-09

This page lists every published CVE security advisory associated with Imagination Technologies. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.