CVE-2026-16280

Summary

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.

Affected Software

VendorProductVersion RangeStatus
Imagination TechnologiesGraphics DDK1.18 RTM2affected
Imagination TechnologiesGraphics DDK23.2 RTM2affected
Imagination TechnologiesGraphics DDK24.2 RTM2affected
Imagination TechnologiesGraphics DDK25.1 RTM2 <= 25.3 RTMaffected
Imagination TechnologiesGraphics DDK26.1 RTM1affected
Imagination TechnologiesGraphics DDK26.1 RTM2unaffected

Weaknesses

  • CWE-190: CWE-190: Integer Overflow or Wraparound

References