7.3

CVE-2026-21733

GPU DDK - Incorrect flags validation in RGXDerivePTEProt8 can allow GPU to overwrite read-only shared memory (e.g. libc.so)

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory and files.



This is caused by improper handling of GPU memory reservation protections.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imaginationtech ≫ Ddk Version < 25.3
   Google ≫ Android Version -
   Linux ≫ Linux Kernel Version -
Imaginationtech ≫ Ddk Version 25.3 Update rtm
   Google ≫ Android Version -
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.01
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.3 1.8 5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-280 Improper Handling of Insufficient Permissions or Privileges

The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state.

https://www.imaginationtech.com/gpu-driver-vulnerabilities/
Vendor Advisory