Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-21734: CWE-823: Use of Out-of-range Pointer Offset (4.16) in Imagination Technologies Graphics DDK

0
Unknown
VulnerabilityCVE-2026-21734cvecve-2026-21734cwe-823
Published: 06/26/2026 (06/26/2026, 15:14:00 UTC)
Source: CVE Database V5
Vendor/Project: Imagination Technologies
Product: Graphics DDK

Description

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device. An edge case using a very small value in GPU shader code can cause a segmentation fault in the GPU shader compiler due to am out-of-bounds write.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/26/2026, 16:22:31 UTC

Technical Analysis

This vulnerability involves a use of out-of-range pointer offset (CWE-823) in the GPU shader compiler library of Imagination Technologies Graphics DDK. Specifically, unusual GPU shader code containing a very small value can cause an out-of-bounds write leading to a crash (segmentation fault) in the compiler process. The issue arises during the compilation of GPU shader code loaded from a web page. On certain platforms where the compiler process has system-level privileges, this could enable escalation of privileges or other exploits.

Potential Impact

The vulnerability can cause a crash of the GPU shader compiler process due to an out-of-bounds write. On platforms where the compiler process runs with system privileges, this crash could be exploited to achieve further compromise of the device. No known exploits are reported in the wild at this time.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround has been documented. Users should monitor for vendor updates and advisories from Imagination Technologies regarding this issue.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
imaginationtech
Date Reserved
2026-01-05T11:57:27.258Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null

Threat ID: 6a3ea39f6e08203f7db8ff87

Added to database: 06/26/2026, 16:06:55 UTC

Last enriched: 06/26/2026, 16:22:31 UTC

Last updated: 06/26/2026, 18:34:33 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses