CVE-2026-16280: GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset
Published Jul 24, 2026
·Updated
An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
Affected Software
5 affected components
GPU DDK
All of the following
Any of the following
Imaginationtech Ddk<26.1
Imaginationtech Ddk=26.1-rtm1
Any of the following
Google Android
Linux Linux kernel
Event History
Jul 24, 2026
CVE Published
via MITRE·10:02 PM
Data Sourced
via MITRE·10:02 PM
DescriptionWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-16280?
The severity of CVE-2026-16280 is rated at 58.
2
How do I fix CVE-2026-16280?
To fix CVE-2026-16280, update the GPU DDK to the latest version provided by the vendor.
3
What is the impact of CVE-2026-16280?
CVE-2026-16280 can result in incorrect GPU MMU mappings, potentially allowing access to unintended physical memory.
4
Who is affected by CVE-2026-16280?
Non-privileged users of systems utilizing GPU DDK are potentially affected by CVE-2026-16280.
5
What type of vulnerability is CVE-2026-16280?
CVE-2026-16280 is classified as an integer overflow vulnerability.