{"api_version":"1","generated_at":"2026-08-07T04:18:14+00:00","cve":"CVE-2026-49746","urls":{"html":"https://cve.report/CVE-2026-49746","api":"https://cve.report/api/cve/CVE-2026-49746.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-49746","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-49746"},"summary":{"title":"GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem","description":"Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages.\n\n\n\nIncorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.","state":"PUBLISHED","assigner":"imaginationtech","published_at":"2026-08-07 03:16:20","updated_at":"2026-08-07 03:16:20"},"problem_types":["CWE-823","CWE-823 CWE - CWE-823: Use of Out-of-range Pointer Offset (4.16)"],"metrics":[],"references":[{"url":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/","name":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/","refsource":"367425dc-4d06-4041-9650-c2dc6aaa27ce","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-49746","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49746","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Imagination Technologies","product":"Graphics DDK","version":"affected 1.18 RTM2 custom","platforms":["Linux","Android"]},{"source":"CNA","vendor":"Imagination Technologies","product":"Graphics DDK","version":"affected 23.2 RTM2 custom","platforms":["Linux","Android"]},{"source":"CNA","vendor":"Imagination Technologies","product":"Graphics DDK","version":"affected 24.2 RTM2 custom","platforms":["Linux","Android"]},{"source":"CNA","vendor":"Imagination Technologies","product":"Graphics DDK","version":"affected 25.1 RTM2 25.3 RTM custom","platforms":["Linux","Android"]},{"source":"CNA","vendor":"Imagination Technologies","product":"Graphics DDK","version":"affected 26.1 RTM1 custom","platforms":["Linux","Android"]},{"source":"CNA","vendor":"Imagination Technologies","product":"Graphics DDK","version":"unaffected 26.1 RTM2 custom","platforms":["Linux","Android"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unknown","platforms":["Linux","Android"],"product":"Graphics DDK","vendor":"Imagination Technologies","versions":[{"status":"affected","version":"1.18 RTM2","versionType":"custom"},{"status":"affected","version":"23.2 RTM2","versionType":"custom"},{"status":"affected","version":"24.2 RTM2","versionType":"custom"},{"lessThanOrEqual":"25.3 RTM","status":"affected","version":"25.1 RTM2","versionType":"custom"},{"status":"affected","version":"26.1 RTM1","versionType":"custom"},{"status":"unaffected","version":"26.1 RTM2","versionType":"custom"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages.</p><p>Incorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.&nbsp;</p>"}],"value":"Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages.\n\n\n\nIncorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages."}],"impacts":[{"capecId":"CAPEC-679","descriptions":[{"lang":"en","value":"CAPEC - CAPEC-679: Exploitation of Improperly Configured or Implemented Memory Protections (Version 3.9)"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-823","description":"CWE - CWE-823: Use of Out-of-range Pointer Offset (4.16)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-07T01:59:38.642Z","orgId":"367425dc-4d06-4041-9650-c2dc6aaa27ce","shortName":"imaginationtech"},"references":[{"url":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/"}],"source":{"discovery":"UNKNOWN"},"title":"GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"367425dc-4d06-4041-9650-c2dc6aaa27ce","assignerShortName":"imaginationtech","cveId":"CVE-2026-49746","datePublished":"2026-08-07T01:59:38.642Z","dateReserved":"2026-06-01T11:03:13.032Z","dateUpdated":"2026-08-07T01:59:38.642Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-07 03:16:20","lastModifiedDate":"2026-08-07 03:16:20","problem_types":["CWE-823","CWE-823 CWE - CWE-823: Use of Out-of-range Pointer Offset (4.16)"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"49746","Ordinal":"1","Title":"GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhy","CVE":"CVE-2026-49746","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"49746","Ordinal":"1","NoteData":"Software installed and run as a non-privileged user may conduct improper GPU system calls to cause OOB read kernel memory access and in certain cases cause GPU UAF of arbitrary pages.\n\n\n\nIncorrect validation of array index can lead to OOB read and potentially to GPU UAF of arbitrary pages.","Type":"Description","Title":"GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhy"}]}}}