CVE-2026-22163 describes an insufficient synchronization vulnerability (CWE-820) in an unspecified product's DDK kernel module. This flaw allows pre-existing malware to misuse the IOCTL interface, enabling the GPU to perform writes to arbitrary physical memory pages. Exploitation requires local access and the presence of malware, leading to a severe impact of arbitrary physical memory manipulation. Despite the critical potential impact, the vulnerability has an extremely low EPSS score of 0.00017, with no known active exploitation, public exploit code, or community attention. It is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 25.1, <= 25.3CPE matchmatch criteria | cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:* | ||
1.17CPE matchmatch criteria | cpe:2.3:a:imaginationtech:ddk:1.17:*:*:*:*:*:*:* | ||
1.18CPE matchmatch criteria | cpe:2.3:a:imaginationtech:ddk:1.18:*:*:*:*:*:*:* | ||
23.2CPE matchmatch criteria | cpe:2.3:a:imaginationtech:ddk:23.2:*:*:*:*:*:*:* | ||
24.1CPE matchmatch criteria | cpe:2.3:a:imaginationtech:ddk:24.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.