PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-45202 Imagination Technologies CVE debrief

Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption. Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event. The vulnerability is caused by memory free paths not maintaining state data of upgraded higher order allocations, which could lead to memory leaks or double free events. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. System administrators and users of Unknown Vendor software, particularly those using Imagination Technologies GPU drivers, should review and apply vendor patches or updates, monitor system logs for signs of memory leaks or corruption, and implement compensating controls to limit potential damage.

Vendor
Imagination Technologies
Product
Graphics DDK
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-09-03
Advisory published
2026-08-21
Advisory updated
2026-09-03

Who should care

System administrators and users of Unknown Vendor software, particularly those using Imagination Technologies GPU drivers, should review and apply vendor patches or updates, monitor system logs for signs of memory leaks or corruption, and implement compensating controls to limit potential damage. Security teams should prioritize patching and verify affected product deployments.

Technical summary

The vulnerability occurs when software installed and run as a non-privileged user conducts GPU system calls, potentially causing GPU memory leaks and kernel heap corruption. This is due to memory free paths not maintaining state data of upgraded higher order allocations, which could lead to memory leaks or double free events. The vulnerability affects Imagination Technologies GPU drivers and could allow an attacker to cause memory leaks or kernel heap corruption. Defenders should prioritize patching and verify affected product deployments.

Defensive priority

Medium priority due to potential for memory leaks and kernel heap corruption

Recommended defensive actions

  • Review and apply vendor patches or updates
  • Monitor system logs for signs of memory leaks or corruption
  • Implement compensating controls to limit potential damage
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Evidence from official CVE Program record and NVD vulnerability detail page. Limited information available on affected scope and vendor remediation. The vulnerability is caused by memory free paths not maintaining state data of upgraded higher order allocations, which could lead to memory leaks or double free events. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-45202 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-45202

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-45202 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45202

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.imaginationtech.com/gpu-driver-vulnerabilities/

    367425dc-4d06-4041-9650-c2dc6aaa27ce

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.