{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-41158",
        "assignerOrgId": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
        "state": "PUBLISHED",
        "assignerShortName": "imaginationtech",
        "dateReserved": "2026-04-17T16:26:03.731Z",
        "datePublished": "2026-06-12T21:57:29.607Z",
        "dateUpdated": "2026-06-15T19:26:18.813Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
                "shortName": "imaginationtech",
                "dateUpdated": "2026-06-12T21:57:29.607Z"
            },
            "title": "GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrink",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-416",
                            "description": "CWE-416: Use After Free",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-124",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-124: Shared Resource Manipulation"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Imagination Technologies",
                    "product": "Graphics DDK",
                    "platforms": [
                        "Linux",
                        "Android"
                    ],
                    "versions": [
                        {
                            "status": "unaffected",
                            "version": "1.18 RTM",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "23.2 RTM",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "24.2 RTM",
                            "versionType": "custom"
                        },
                        {
                            "status": "affected",
                            "version": "25.1 RTM",
                            "lessThanOrEqual": "25.3 RTM",
                            "versionType": "custom"
                        },
                        {
                            "status": "affected",
                            "version": "26.1 RTM",
                            "versionType": "custom"
                        },
                        {
                            "status": "unaffected",
                            "version": "26.2 RTM",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unknown"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages.\n\n\n\nPhysical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>Software installed and run as a non-privileged user may conduct GPU system calls to write to arbitrary freed physical pages.\n<br>\n<br>Physical memory allocated and freed, without the deferred free mechanism can lead to those resources being used for read/write by the GPU after the kernel module has freed the resource.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 7.8,
                            "attackVector": "LOCAL",
                            "baseSeverity": "HIGH",
                            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                            "integrityImpact": "HIGH",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "LOW",
                            "confidentialityImpact": "HIGH"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-06-15T18:50:52.946060Z",
                                "id": "CVE-2026-41158",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-06-15T19:26:18.813Z"
                }
            }
        ]
    }
}