PT-2026-64421 · Gpu Ddk · Gpu Ddk

CVE-2026-16280

·

Published

2026-07-24

·

Updated

2026-07-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPU DDK (affected versions not specified)
Description An integer overflow occurs during the calculation of physical offsets for sparse PMRs (Partial Memory Regions) within the PMRLogicalOffsetToPhysicalOffset() function. For PMRs larger than 4 GB, this results in 32-bit truncation of address computations, leading to incorrect GPU MMU (Memory Management Unit) mappings. Consequently, a non-privileged user could trigger access to unintended physical memory, potentially causing memory corruption or information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16280

Affected Products

Gpu Ddk