{"id":"CVE-2026-7639","title":"Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code.\n\n\n\nTriggering failure path in the …","summary":"Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code.\n\n\n\nTriggering failure path in the …","severity":"none","cwe":["CWE-459"],"published":"2026-07-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7639","references":[{"url":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/","label":"367425dc-4d06-4041-9650-c2dc6aaa27ce"}],"tags":["nvd"],"epss":0.00179,"epssPercentile":0.07725,"ingestedAt":"2026-07-11T21:15:42.247Z","slug":"CVE-2026-7639","body":"## Overview\n\nSoftware installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code.\n\n\n\nTriggering failure path in the MMU mapping logic by a malicious code could lead to incomplete cleanup of an internal driver state, allowing for future unauthorized access to the contents of the physical memory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}