Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.
History

Mon, 15 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 13 Jun 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech graphics Ddk
Vendors & Products Imaginationtech
Imaginationtech graphics Ddk

Fri, 12 Jun 2026 22:15:00 +0000

Type Values Removed Values Added
Description Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages. Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.
Title GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrink
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published: 2026-06-12T21:57:29.607Z

Updated: 2026-06-15T19:26:18.813Z

Reserved: 2026-04-17T16:26:03.731Z

Link: CVE-2026-41158

cve-icon Vulnrichment

Updated: 2026-06-15T18:51:34.364Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T22:16:50.693

Modified: 2026-06-16T15:40:10.107

Link: CVE-2026-41158

cve-icon Redhat

No data.