CVE-2026-41154
גבוהה 7.8
תיאור (מקור, אנגלית)
Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. When indexing pages larger than 4kB in the page freeing logic of the sparse memory implementation, incorrect buffer indexing leads to OOB access.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-17/8/2026
- CWE
- CWE-787
מוצרים מושפעים
imaginationtech: ddk; google: android; linux: linux kernel
קישורים
- https://www.imaginationtech.com/gpu-driver-vulnerabilities/ Vendor Advisory