Back

HIGH

GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable

Published May 1, 2026

Description

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable subsequent exploit on the system.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner imaginationtech
Published May 1, 2026
Updated May 1, 2026
Reserved Jan 6, 2026
CISA Vulnrichment
Updated May 1, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a