CVE-2026-21736General(imaginationtech / ddk)

LOWCVSS 4.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is caused by improper handling of the memory protections for the user-mode wrapped memory resource.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-280

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ddk

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
ddk

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-09: 3Technical Details · 2026-03-09: 303-09
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-21736 Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to read-only wrapped user-mode memory. This is cau… https://www.cve.org/CVERecord?id=CVE-2026-21736

    Post summary

    The tweet cites CVE-2026-21736 and provides a terse technical description but offers no PoC, exploit code, active exploitation evidence, patch, or debunking claim.

    0000097
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-21736 GPU Memory Protection Bypass via Improper System Call Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21736

    Post summary

    The post only references CVE-2026-21736 with a brief description and a URL, lacking further actionable details.

    0000064
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-21736 - GPU DDK - Insufficient permission check in PhysmemWrapExtMem() when write attribute support enabled Intel Report: https://ift.tt/Y2GmQf0

    Post summary

    The tweet announces a new CVE-2026-21736, describing an insufficient permission check in GPU DDK, and provides a link to Intel’s report, but no PoC, exploit, or patch details are included.

    0000033
    347 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appimaginationtechddk25.1--
Appimaginationtechddk25.1--

Explore more