Sensitive Information in Resource Not Removed Before Reuse in PowerVR GPU DDK - #VU148436

 

Sensitive Information in Resource Not Removed Before Reuse in PowerVR GPU DDK - #VU148436

Published: September 9, 2026


Vulnerability identifier: #VU148436
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-226
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose past data.

The vulnerability exists due to improper cache cleaning in PhysmemWrapExtMem when mapping imported pages uncached. A local user can cause the GPU to read imported pages with stale cache contents to disclose past data.


Affected software

PowerVR GPU DDK

Remediation

Install security update from vendor's website.

PowerVR GPU DDK - update to 26.1 RTM2

External References

Related Security Bulletins