Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Imagination Technologies — Vulnerabilities & Security Advisories 85

Browse all 85 CVE security advisories affecting Imagination Technologies. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Imagination Technologies specializes in graphics processing units and multimedia technologies, primarily supplying intellectual property licenses to semiconductor manufacturers for embedded systems and mobile devices. With fifty-nine recorded Common Vulnerabilities and Exposures, the company’s historical attack surface has predominantly featured remote code execution and buffer overflow flaws within its proprietary middleware and driver software. These vulnerabilities often stem from insufficient input validation in image processing pipelines, allowing attackers to escalate privileges or execute arbitrary code on affected endpoints. While no single catastrophic breach has defined the firm’s public security narrative, the cumulative impact of these CVEs highlights risks in its embedded software stack. Security assessments indicate that many issues were resolved through routine firmware updates, yet the persistent presence of memory corruption bugs suggests ongoing challenges in securing complex, low-level hardware abstractions used across diverse consumer electronics.

Top products by Imagination Technologies: Graphics DDK
CVE ID Title CVSS Severity Published
CVE-2026-22163 GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU — Graphics DDK CWE-820 8.4 - 2026-03-20
CVE-2026-21732 GPU DDK - libusc OOB write at ConvertSwitchToArrayLookupBP during WebGPU shader compilation — Graphics DDK CWE-823 8.1 - 2026-03-20
CVE-2026-21736 GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled — Graphics DDK CWE-280 7.1AI High AI 2026-03-09
CVE-2025-13952 GPU DDK - libusc UAF via WebGPU shaders at MergeConsecutiveBarriersBP — Graphics DDK CWE-416 9.8 - 2026-01-24
CVE-2025-10865 GPU DDK - DevmemIntGetReservationData does not ref the PMR it returns — Graphics DDK CWE-416 7.8AI High AI 2026-01-13
CVE-2025-58411 GPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAF — Graphics DDK CWE-416 7.8AI High AI 2026-01-13
CVE-2025-58409 GPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical memory writes corrupting memory — Graphics DDK CWE-119 7.8AI High AI 2026-01-13
CVE-2025-25176 GPU DDK - GPU Register value contents leaked from secure workloads to non-secure world — Graphics DDK CWE-668 8.1AI High AI 2026-01-13
CVE-2025-58408 GPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling code — Graphics DDK CWE-416 5.5AI Medium AI 2025-12-01
CVE-2025-58407 GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSet — Graphics DDK CWE-367 7.8AI High AI 2025-11-17
CVE-2025-58410 GPU DDK - Multiple calls into PhysmemGEMPrimeExport can inherit write access permission for an existing read-only dma_buf import PMR — Graphics DDK CWE-280 7.8AI High AI 2025-11-17
CVE-2025-46711 GPU DDK - NULL Pointer dereference occurs in LockHandle on bridge entry when connection misused — Graphics DDK CWE-476 5.5AI Medium AI 2025-09-22
CVE-2025-25177 GPU DDK - Roll-back of pvr_exp_fence not in finalised state can cause UAF — Graphics DDK CWE-416 7.8AI High AI 2025-09-22
CVE-2025-46709 GPU DDK - Security fix for PP-171570 can lead to an uninitialised pointer dereference and memory leak — Graphics DDK CWE-416 7.1 - 2025-08-08
CVE-2025-6573 GPU DDK - RGXFW_CTL.pui8FWScratchBuf Leak/Overwrite — Graphics DDK CWE-280 5.5 - 2025-08-08
CVE-2025-8109 GPU DDK - GPU shader shared memory corrupted using ptrace to disrupt GPU operation — Graphics DDK CWE-280 7.1AI High AI 2025-08-04
CVE-2025-25180 GPU DDK - Insufficient validation in RGXCREATEFREELIST creates corrupt freelist — Graphics DDK CWE-823 5.5AI Medium AI 2025-07-14
CVE-2025-46708 GPU DDK - Guest VM can delay the FW and GPU from processing workloads from other VMs — Graphics DDK CWE-280 5.5AI Medium AI 2025-06-27
CVE-2025-46707 GPU DDK - Guest VM can override its own FW VZ connection state after the FW has close it — Graphics DDK CWE-668 7.8AI High AI 2025-06-27
CVE-2025-46710 Imagination GPU Driver 安全漏洞 — Graphics DDK CWE-416 7.8AI High AI 2025-06-16
CVE-2025-25179 GPU DDK - Freelist GPU VA can be remapped to another reservation/PMR to trigger GPU arbitrary write to physical memory — Graphics DDK CWE-280 7.8AI High AI 2025-06-02
CVE-2024-47893 GPU DDK - OOB read and write of the shared KMD/FW memory heap (VZ/TEE setups) — Graphics DDK CWE-823 8.4AI High AI 2025-05-17
CVE-2025-1706 GPU DDK - Improper locking when accessing the pvr_exp_fence object — Graphics DDK CWE-416 7.8AI High AI 2025-05-17
CVE-2025-0467 GPU DDK - rgxfw_hwperf_get_packet_buffer OOB write — Graphics DDK CWE-823 7.8 - 2025-04-18
CVE-2025-25178 GPU DDK - PhysmemWrapExtMem uiSize=0 corrupts kernel memory — Graphics DDK CWE-1284 7.8AI High AI 2025-04-04
CVE-2025-0468 GPU DDK - ui64RobustnessAddress can overwrite Freelist / HWRT (and bypass PMMETA) — Graphics DDK CWE-280 5.5AI Medium AI 2025-04-04
CVE-2025-0835 GPU DDK - _WrapExtMemReleasePages called twice if _FlushUMVirtualRange fails — Graphics DDK CWE-416 7.8AI High AI 2025-03-24
CVE-2025-0478 GPU DDK - PMMETA_PROTECT PMR can be exported as dma-buf file / GEM object — Graphics DDK CWE-280 5.5AI Medium AI 2025-03-24
CVE-2024-12837 GPU DDK - Exploitable kernel double free on apsFenceSyncCheckpoints allocated with arbitrary size — Graphics DDK CWE-416 7.8 - 2025-03-07
CVE-2024-12576 GPU DDK - Untrusted app can crash firmware by forcing MCU access to non-aligned address — Graphics DDK CWE-822 5.5 - 2025-03-07

This page lists every published CVE security advisory associated with Imagination Technologies. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.