CVE Explorer
CVE-2026-41155
An attacker could cooperatively pass data from one secure GPU process to another secure GPU process through shared secure memory allocations in the kernel module. Additionally, an attacker could disrupt the operation of another secure GPU process leading to image corruption / GPU hardware recovery.
Sharing secure memory allocations among various GPU secure processes allows an attacker to corrupt shared resource affecting other users.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","platforms":["Linux","Android"],"product":"Graphics DDK","vendor":"Imagination Technologies","versions":[{"status":"affected","version":"1.18 RTM","versionType":"custom"},{"status":"affected","version":"23.2 RTM","versionType":"custom"},{"status":"affected","version":"24.2 RTM","versionType":"custom"},{"lessThanOrEqual":"25.3 RTM","status":"affected","version":"25.1 RTM","versionType":"custom"},{"status":"affected","version":"26.1 RTM","versionType":"custom"},{"status":"unaffected","version":"26.2 RTM","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:3acd7e8d38b9376f09da734307571a6429ba49682b7f604fa2bdfb58e78ddbe6 · sha256:a04e220f8f7ee9b8… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:3acd7e8d38b9376f09da734307571a6429ba49682b7f604fa2bdfb58e78ddbe6 · sha256:a04e220f8f7ee9b8… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-653","description":"CWE-653: Improper Isolation or Compartmentalization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:3acd7e8d38b9376f09da734307571a6429ba49682b7f604fa2bdfb58e78ddbe6 · sha256:a04e220f8f7ee9b8… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:3acd7e8d38b9376f09da734307571a6429ba49682b7f604fa2bdfb58e78ddbe6 · sha256:a04e220f8f7ee9b8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.