Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Imagination Technologies — Vulnerabilities & Security Advisories 85

Browse all 85 CVE security advisories affecting Imagination Technologies. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Imagination Technologies specializes in graphics processing units and multimedia technologies, primarily supplying intellectual property licenses to semiconductor manufacturers for embedded systems and mobile devices. With fifty-nine recorded Common Vulnerabilities and Exposures, the company’s historical attack surface has predominantly featured remote code execution and buffer overflow flaws within its proprietary middleware and driver software. These vulnerabilities often stem from insufficient input validation in image processing pipelines, allowing attackers to escalate privileges or execute arbitrary code on affected endpoints. While no single catastrophic breach has defined the firm’s public security narrative, the cumulative impact of these CVEs highlights risks in its embedded software stack. Security assessments indicate that many issues were resolved through routine firmware updates, yet the persistent presence of memory corruption bugs suggests ongoing challenges in securing complex, low-level hardware abstractions used across diverse consumer electronics.

Top products by Imagination Technologies: Graphics DDK
CVE ID Title CVSS Severity Published
CVE-2026-45202 GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast` — Graphics DDK CWE-415 - - 2026-08-21
CVE-2026-45201 GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read and/or write of arbitrary physical memory — Graphics DDK CWE-1284 - - 2026-08-21
CVE-2026-45199 GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers — Graphics DDK CWE-823 - - 2026-08-21
CVE-2026-49746 GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem — Graphics DDK CWE-823 - - 2026-08-07
CVE-2026-45204 GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory — Graphics DDK CWE-476 - - 2026-08-07
CVE-2026-45198 GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted — Graphics DDK CWE-822 - - 2026-08-07
CVE-2026-16280 GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset — Graphics DDK CWE-190 - - 2026-07-24
CVE-2026-49745 GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0 — Graphics DDK CWE-823 - - 2026-07-24
CVE-2026-49744 GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() — Graphics DDK CWE-823 - - 2026-07-24
CVE-2026-49743 GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed — Graphics DDK CWE-416 - - 2026-07-24
CVE-2026-45203 GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU — Graphics DDK CWE-367 - - 2026-07-10
CVE-2026-45196 GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel — Graphics DDK CWE-280 - - 2026-07-10
CVE-2026-7639 GPU DDK - Page UAF read in PMMETA_PROTECT heap memory — Graphics DDK CWE-459 - - 2026-07-10
CVE-2026-41154 GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse — Graphics DDK CWE-787 - - 2026-07-10
CVE-2026-34196 GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem — Graphics DDK CWE-416 - - 2026-07-10
CVE-2026-45195 GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted — Graphics DDK CWE-280 - - 2026-06-26
CVE-2026-21734 GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation — Graphics DDK CWE-823 - - 2026-06-26
CVE-2026-41156 GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference — Graphics DDK CWE-416 - - 2026-06-19
CVE-2026-34192 GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries — Graphics DDK CWE-416 - - 2026-06-19
CVE-2026-41158 GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrink — Graphics DDK CWE-416 - - 2026-06-12
CVE-2026-41157 GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D — Graphics DDK CWE-787 - - 2026-06-12
CVE-2026-41155 GPU DDK - SharedSecMem mapped into all GPU virtual address spaces — Graphics DDK CWE-653 - - 2026-06-12
CVE-2026-34195 GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexes — Graphics DDK CWE-787 - - 2026-06-12
CVE-2026-34194 GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count — Graphics DDK CWE-468 - - 2026-06-08
CVE-2026-22164 GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical — Graphics DDK CWE-122 - - 2026-06-08
CVE-2026-34193 GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr() — Graphics DDK CWE-823 - - 2026-06-01
CVE-2026-22166 GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable — Graphics DDK CWE-416 8.8 - 2026-05-01
CVE-2026-22165 GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBs — Graphics DDK CWE-416 8.8 - 2026-05-01
CVE-2026-22167 GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory — Graphics DDK CWE-119 7.8 - 2026-05-01
CVE-2026-21733 GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so) — Graphics DDK CWE-280 7.1AI High AI 2026-04-17

This page lists every published CVE security advisory associated with Imagination Technologies. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.