Vulnerabilidades em Imagination Technologies

87 resultados
Análise Vexday

Com 68 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), a Imagination Technologies apresenta taxa de exploração abaixo da média geral do catálogo, o que sugere risco operacional imediato relativamente contido. No entanto, 13 vulnerabilidades surgiram nos últimos 90 dias, indicando cadência recente de descobertas que merece acompanhamento. A falha mais comum é CWE-416 (Use-After-Free), categoria historicamente associada a primitivas de execução de código arbitrário, e a CVE mais relevante no momento é CVE-2024-47897, com escore EPSS de 0,0058 — baixo, porém não negligenciável dado o tipo de fraqueza predominante. Das 5 CVEs classificadas como críticas e sem nenhuma prova de conceito pública conhecida, a ausência de PoC reduz a superfície de exploração imediata, mas não elimina a necessidade de priorizar correção, especialmente em ambientes com exposição de drivers ou firmware baseados nessa tecnologia.

CVE-2026-34196HIGHGPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMemEPSS 0.2%CVE-2025-58411HIGHGPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAFEPSS 0.2%CVE-2024-47900HIGHGPU DDK - Multiple integer overflow in DmaTransfer PMR_DevPhysAddr functions leading to OOB writesEPSS 0.2%CVE-2025-0835HIGHGPU DDK - _WrapExtMemReleasePages called twice if _FlushUMVirtualRange failsEPSS 0.2%CVE-2024-12837HIGHGPU DDK - Exploitable kernel double free on apsFenceSyncCheckpoints allocated with arbitrary sizeEPSS 0.2%CVE-2026-34192HIGHGPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entriesEPSS 0.2%CVE-2026-41156HIGHGPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding referenceEPSS 0.2%CVE-2026-21734HIGHGPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilationEPSS 0.2%CVE-2024-47896LOWGPU DDK - rgxfw_hwr_log_info OOB write via psHWRInfoBuf->ui32WriteIndexEPSS 0.2%CVE-2024-46974HIGHGPU DDK - Arbitrary write of read-only dmabufEPSS 0.2%CVE-2026-22167HIGHGPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memoryEPSS 0.2%CVE-2024-46975HIGHGPU DDK - rgxfw_write_robustness_buffer allows arbitrary catreg set mappingEPSS 0.2%CVE-2025-58409LOWGPU DDK - Disguised freelist buffers passed to RGXCreateHWRTDataSet can cause arbitrary physical memory writes corrupting memoryEPSS 0.1%CVE-2024-12576MEDIUMGPU DDK - Untrusted app can crash firmware by forcing MCU access to non-aligned addressEPSS 0.1%CVE-2024-43705HIGHGPU DDK - Security: Exploitable PVRSRVBridgePhysmemWrapExtMem may lead to overwrite read-only file/memory (e.g. libc.so)EPSS 0.1%CVE-2025-0478HIGHGPU DDK - PMMETA_PROTECT PMR can be exported as dma-buf file / GEM objectEPSS 0.1%CVE-2026-45196HIGHGPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernelEPSS 0.1%CVE-2026-45195HIGHGPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrustedEPSS 0.1%CVE-2026-34193MEDIUMGPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()EPSS 0.1%CVE-2025-25177MEDIUMGPU DDK - Roll-back of pvr_exp_fence not in finalised state can cause UAFEPSS 0.1%