Sensitive Information in Resource Not Removed Before Reuse in PowerVR GPU DDK - #VU148436
Published: September 9, 2026
Vulnerability identifier: #VU148436
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-226
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to disclose past data.
The vulnerability exists due to improper cache cleaning in PhysmemWrapExtMem when mapping imported pages uncached. A local user can cause the GPU to read imported pages with stale cache contents to disclose past data.
Affected software
PowerVR GPU DDK
Remediation
Install security update from vendor's website.
PowerVR GPU DDK - update to 26.1 RTM2