CVE-2026-21736: GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory.
This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21736?
CVE-2026-21736 is classified as a high-severity vulnerability due to the potential for unauthorized access to read-only memory.
How do I fix CVE-2026-21736?
To remediate CVE-2026-21736, update the Imagination Technologies GPU DDK to the latest version that addresses this permission issue.
What are the potential consequences of CVE-2026-21736?
Exploitation of CVE-2026-21736 may allow non-privileged users to manipulate GPU system calls, potentially leading to memory corruption or unauthorized data access.
Which software is affected by CVE-2026-21736?
CVE-2026-21736 affects the Imagination Technologies DDK version 25.1 and its variant 25.1-rtm2.
Can CVE-2026-21736 be exploited remotely?
CVE-2026-21736 is not specifically designed for remote exploitation, as it primarily requires local access to the system.