PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-22164 Imagination Technologies CVE debrief

CVE-2026-22164 is a HIGH severity vulnerability with a CVSS score of 7.5. The vulnerability allows software installed and run as a non-privileged user to conduct improper GPU system calls, potentially corrupting kernel heap memory. An exploit can be used to corrupt kernel memory by creating resources of certain types and presenting a set of parameters to the affected interface.

Vendor
Imagination Technologies
Product
Graphics DDK
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-08
Original CVE updated
2026-06-09
Advisory published
2026-06-08
Advisory updated
2026-06-09

Who should care

Users of the affected product from Unknown Vendor should take immediate action to assess and mitigate the risk associated with this vulnerability.

Technical summary

The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. It is classified under CWE-122.

Defensive priority

HIGH

Recommended defensive actions

  • Assess the vulnerability's impact on your organization.
  • Apply patches or mitigations provided by the vendor, if available. See resourceLinkAnnotations [ref-4] for more information.
  • Restrict access to the affected interface to only privileged users.

Evidence notes

The vendor is listed as Unknown Vendor, but there is evidence suggesting the vendor might be Imaginationtech [source-item].

Official resources

CVE-2026-22164 was published on 2026-06-08T16:16:37.823Z and modified on 2026-06-09T13:57:49.980Z.