
Imagination Graphics DDK: GPU firmware boots using a save/restore pointer the non-secure kernel can rewrite
Impact
When the GPU firmware spills its internal state from tightly coupled private memory out to main memory and reads it back, it follows a pointer that lives in non-secure Rich Execution Environment memory. A compromised non-secure kernel can change that pointer, so the firmware boots on data the attacker chose. This breaks the direction of trust a TEE deployment is built on: the secure GPU thread of control is supposed to be protected from the non-secure OS, and here the non-secure OS steers it. Vendor score is 7.8 local with full confidentiality, integrity and availability loss. As with the rest of this vendor's DDK advisories, PowerVR-class parts are embedded and SoC silicon, not NVIDIA or AMD datacenter accelerators, so this matters only to operators running such platforms with TEE support enabled.
Who can reach it
Local, and it requires the attacker to already hold kernel privileges in the non-secure OS. The value is not the initial foothold, it is crossing from a compromised REE kernel into the secure GPU firmware, so treat it as a post-exploitation escalation rather than an entry point.
What to do
Imagination publishes fixed DDK versions on its GPU driver vulnerabilities page; the record states no version. Delivery is through the SoC vendor BSP, so you are waiting on a platform-vendor driver and firmware drop rather than a package update. Installing it replaces the kernel-mode driver and GPU firmware and needs a reboot of the affected node. There is no configuration-level mitigation once the non-secure kernel is compromised, so the pre-patch posture is keeping REE kernel compromise out of reach.
References
Related entries
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): A correctness defect in the amdgpuCVE-2026-45853 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-46263 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu/userq): A correctness defect in the amdgpuCVE-2026-46311 · Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu/userq)High
- TensorRT-LLM: RCE via insecure deserialization on model loadCVE-2026-47472 · TensorRT-LLMHigh
- Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu): A double free in the amdgpu user-modeCVE-2026-52987 · Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-53136 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.