CVE-2026-22166: GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22166?
CVE-2026-22166 is a high severity vulnerability due to its potential to cause a write after free condition in the GPU DDK.
How do I fix CVE-2026-22166?
To fix CVE-2026-22166, users should update the GPU DDK to the latest version provided by the vendor.
What is the impact of CVE-2026-22166?
CVE-2026-22166 can lead to crashes in the GPU GLES user-space shared library, affecting the stability of applications using WebGPU.
Who is affected by CVE-2026-22166?
CVE-2026-22166 affects users on platforms utilizing the vulnerable GPU DDK with WebGPU support.
How can CVE-2026-22166 be exploited?
CVE-2026-22166 can be exploited by loading a specially crafted web page that contains unusual WebGPU content.