CVE-2026-16280

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*
cpe:2.3:a:imaginationtech:ddk:26.1:rtm1:*:*:*:*:*:*
OR cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-24 23:16

Updated : 2026-08-12 18:50


NVD link : CVE-2026-16280

Mitre link : CVE-2026-16280

CVE.ORG link : CVE-2026-16280


JSON object : View

Products Affected

linux

  • linux_kernel

imaginationtech

  • ddk

google

  • android
CWE
CWE-190

Integer Overflow or Wraparound