CVE-2026-22163: GPU DDK - Unsafe writing of MMU PT entries on systems with 32-bit host CPU
Requires malware code to misuse the DDK kernel module IOCTL interface.
Such code can use the interface in an unsupported way that allows subversion of the GPU to perform writes to arbitrary physical memory pages.
The product utilises a shared resource in a concurrent manner but does not attempt to synchronise access to the resource.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22163?
CVE-2026-22163 has a severity rating of 7.8, categorized as high.
How do I fix CVE-2026-22163?
To mitigate CVE-2026-22163, update to the latest version of the Imaginationtech GPU DDK that addresses this vulnerability.
What systems are affected by CVE-2026-22163?
CVE-2026-22163 affects systems with a 32-bit host CPU that utilize the Imaginationtech GPU DDK.
What type of vulnerability is CVE-2026-22163?
CVE-2026-22163 is a vulnerability that allows unsafe writing of MMU page table entries, which can lead to unauthorized memory access.
What can exploit CVE-2026-22163?
Malicious code that improperly uses the DDK kernel module IOCTL interface can exploit CVE-2026-22163 to compromise the GPU.