Vulnerabilities in Imagination Technologies

87 results
Vexday analysis

Com 68 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), a Imagination Technologies apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere risco operacional imediato relativamente contido. No entanto, 13 vulnerabilidades surgiram nos últimos 90 dias, indicando cadência recente de descobertas que merece acompanhamento. A falha mais comum é CWE-416 (Use-After-Free), categoria historicamente associada a primitivas de execução de código arbitrário, e a CVE mais relevante no momento é CVE-2024-47897, com escore EPSS de 0,0058 — baixo, porém não negligenciável dado o tipo de fraqueza predominante. Das 5 CVEs classificadas como críticas e sem nenhuma prova de conceito pública conhecida, a ausência de PoC reduz a superfície de exploração imediata, mas não elimina a necessidade de priorizar correção, especialmente em ambientes com exposição de drivers ou firmware baseados nessa tecnologia.

CVE-2026-45204MEDIUMGPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memoryEPSS 0.2%CVE-2024-46975HIGHGPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mappingEPSS 0.2%CVE-2026-49746HIGHGPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMemEPSS 0.2%CVE-2025-58409LOWGPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical memory writes corrupting memoryEPSS 0.1%CVE-2026-34194HIGHGPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index countEPSS 0.1%CVE-2024-12576MEDIUMGPU DDK - Untrusted app can crash firmware by forcing MCU access to non-aligned addressEPSS 0.1%CVE-2024-43705HIGHGPU DDK - Security: Exploitable PVRSRVBridgePhysmemWrapExtMem may lead to overwrite read-only file/memory (e.g. libc.so)EPSS 0.1%CVE-2025-0478HIGHGPU DDK - PMMETA_PROTECT PMR can be exported as dma-buf file / GEM objectEPSS 0.1%CVE-2026-45196HIGHGPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernelEPSS 0.1%CVE-2026-45195HIGHGPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrustedEPSS 0.1%CVE-2026-41155MEDIUMGPU DDK - SharedSecMem mapped into all GPU virtual address spacesEPSS 0.1%CVE-2026-45202MEDIUMGPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`EPSS 0.1%CVE-2025-25177MEDIUMGPU DDK - Roll-back of pvr_exp_fence not in finalised state can cause UAFEPSS 0.1%CVE-2025-25179HIGHGPU DDK - Freelist GPU VA can be remapped to another reservation/PMR to trigger GPU arbitrary write to physical memoryEPSS 0.1%CVE-2024-47892HIGHGPU DDK - UAF of kernel memory in PMRUnlockPhysAddressesOSMem for on-demand non-4KB PMRs in system memory (UMA)EPSS 0.1%CVE-2024-46971HIGHGPU DDK - UAF of memory in PMRUnlockSysPhysAddressesLocalMem for on-demand PMRs on PCI (LMA) systemsEPSS 0.1%CVE-2025-25180HIGHGPU DDK - Insufficient validation in RGXCREATEFREELIST creates corrupt freelistEPSS 0.1%CVE-2025-46707MEDIUMGPU DDK - Guest VM can override its own FW VZ connection state after the FW has close itEPSS 0.1%CVE-2024-43701HIGHGPU DDK - PowerVR: TLB invalidate UAF of dma_buf imported into multiple GPU devicesEPSS 0.1%CVE-2025-58408MEDIUMGPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling codeEPSS 0.1%