CVE-2026-16280 PUBLISHED

GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset

Assigner: imaginationtech
Reserved: 20.07.2026 Published: 24.07.2026 Updated: 24.07.2026

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.

Product Status

Vendor Imagination Technologies
Product Graphics DDK
Versions Default: unknown
  • Version 1.18 RTM2 is affected
  • Version 23.2 RTM2 is affected
  • Version 24.2 RTM2 is affected
  • affected from 25.1 RTM2 to 25.3 RTM (incl.)
  • Version 26.1 RTM1 is affected
  • Version 26.1 RTM2 is unaffected

References

Problem Types

  • CWE-190: Integer Overflow or Wraparound CWE

Impacts

  • CAPEC-679: Exploitation of Improperly Configured or Implemented Memory Protections (Version 3.9)