PatchSiren cyber security CVE debrief
CVE-2026-45202 Imagination Technologies CVE debrief
Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event. The vulnerability is caused by memory free paths not maintaining state data of upgraded higher order allocations, which could lead to memory leaks or double free events. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. System administrators and users of Unknown Vendor software, particularly those using Imagination Technologies GPU drivers, should review and apply vendor patches or updates, monitor system logs for signs of memory leaks or corruption, and implement compensating controls to limit potential damage.
- Vendor
- Imagination Technologies
- Product
- Graphics DDK
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-03
Who should care
System administrators and users of Unknown Vendor software, particularly those using Imagination Technologies GPU drivers, should review and apply vendor patches or updates, monitor system logs for signs of memory leaks or corruption, and implement compensating controls to limit potential damage. Security teams should prioritize patching and verify affected product deployments.
Technical summary
The vulnerability occurs when software installed and run as a non-privileged user conducts GPU system calls, potentially causing GPU memory leaks and kernel heap corruption. This is due to memory free paths not maintaining state data of upgraded higher order allocations, which could lead to memory leaks or double free events. The vulnerability affects Imagination Technologies GPU drivers and could allow an attacker to cause memory leaks or kernel heap corruption. Defenders should prioritize patching and verify affected product deployments.
Defensive priority
Medium priority due to potential for memory leaks and kernel heap corruption
Recommended defensive actions
- Review and apply vendor patches or updates
- Monitor system logs for signs of memory leaks or corruption
- Implement compensating controls to limit potential damage
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Evidence from official CVE Program record and NVD vulnerability detail page. Limited information available on affected scope and vendor remediation. The vulnerability is caused by memory free paths not maintaining state data of upgraded higher order allocations, which could lead to memory leaks or double free events. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45202 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45202
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45202 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45202
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.imaginationtech.com/gpu-driver-vulnerabilities/
367425dc-4d06-4041-9650-c2dc6aaa27ce
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.