CVE-2026-22163
Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages. The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.08%
- CWE
- CWE-820
- Published
- 2026-03-20
- Last modified
- 2026-03-23
Affected products
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
Weakness type
Related vulnerabilities
- CVE-2026-70637 — LightFTP 2.4 Data Race Condition via ABOR Command in ftpserv.c
- CVE-2026-57029 — Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash
- CVE-2026-44318 — free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF process via concurrent map read/write on Subscriptions
- CVE-2022-50238 — The on-endpoint Microsoft vulnerable driver blocklist is not fully synchronized with the online...
- CVE-2025-49751 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47999 — Windows Hyper-V Denial of Service Vulnerability
- CVE-2025-47154 — LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list...
- CVE-2025-1445 — A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the...