Back to overview

CVE-2026-49743

Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading to read/write UAFs. During workload submission involving a fence exported by the GPU driver, the reference count of the underlying synchronisation primitive is not properly incremented. This can be exploited, by destroying the exported fence and prematurely release the underlying primitive, resulting in a potential use-after-free condition.

Metadata

CVE ID
CVE-2026-49743
State
PUBLISHED
Assigner
imaginationtech
Reserved
2026-06-01 11:03 UTC
Published
2026-07-24 08:42 UTC
Last updated
2026-07-24 08:42 UTC
Primary CWE
CWE-416
CWE-416: Use After Free (4.20)
Vendor / Product
Imagination Technologies / Graphics DDK
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Imagination Technologies Graphics DDK Linux,Android 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 ≤ 25.3 RTM …
Weakness (CWE)
CWESourceDescription
CWE-416 cna CWE-416: Use After Free (4.20)
Back to overview