Vulnerabilities in Imagination Technologies

87 results
Vexday analysis

Com 68 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), a Imagination Technologies apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere risco operacional imediato relativamente contido. No entanto, 13 vulnerabilidades surgiram nos últimos 90 dias, indicando cadência recente de descobertas que merece acompanhamento. A falha mais comum é CWE-416 (Use-After-Free), categoria historicamente associada a primitivas de execução de código arbitrário, e a CVE mais relevante no momento é CVE-2024-47897, com escore EPSS de 0,0058 — baixo, porém não negligenciável dado o tipo de fraqueza predominante. Das 5 CVEs classificadas como críticas e sem nenhuma prova de conceito pública conhecida, a ausência de PoC reduz a superfície de exploração imediata, mas não elimina a necessidade de priorizar correção, especialmente em ambientes com exposição de drivers ou firmware baseados nessa tecnologia.

CVE-2024-47891HIGHGPU DDK - Exploitable double free on PTL_STREAM_DESC object in the kernel function TLServerCloseStreamKM due to a race conditionEPSS 0.2%CVE-2024-46972HIGHGPU DDK - Security: Reference count overflow in pvr_sync_rollback_export_fenceEPSS 0.2%CVE-2026-34196HIGHGPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMemEPSS 0.2%CVE-2025-58411HIGHGPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAFEPSS 0.2%CVE-2024-47900HIGHGPU DDK - Multiple integer overflow in DmaTransfer PMR_DevPhysAddr functions leading to OOB writesEPSS 0.2%CVE-2024-12837HIGHGPU DDK - Exploitable kernel double free on apsFenceSyncCheckpoints allocated with arbitrary sizeEPSS 0.2%CVE-2025-0835HIGHGPU DDK - _WrapExtMemReleasePages called twice if _FlushUMVirtualRange failsEPSS 0.2%CVE-2026-41158HIGHGPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrinkEPSS 0.2%CVE-2026-21734HIGHGPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilationEPSS 0.2%CVE-2026-41156HIGHGPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding referenceEPSS 0.2%CVE-2026-49745HIGHGPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0EPSS 0.2%CVE-2026-45200HIGHGPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by _EncodeAllocationFlagsEPSS 0.2%CVE-2026-45201HIGHGPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read and/or write of arbitrary physical memoryEPSS 0.2%CVE-2026-49743HIGHGPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closedEPSS 0.2%CVE-2026-49744HIGHGPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()EPSS 0.2%CVE-2026-45199HIGHGPU DDK - rgxfw_to_ptr() does not reject FW private data pointersEPSS 0.2%CVE-2026-34192HIGHGPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entriesEPSS 0.2%CVE-2024-47896LOWGPU DDK - rgxfw_hwr_log_info OOB write via psHWRInfoBuf->ui32WriteIndexEPSS 0.2%CVE-2024-46974HIGHGPU DDK - Arbitrary write of read-only dmabufEPSS 0.2%CVE-2026-22167HIGHGPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memoryEPSS 0.2%