Ddk
41 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Ddk, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
Ddk CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 4 |
| 2025-03 | 2 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 4 |
| 2025-07 | 0 |
| 2025-08 | 1 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 2 |
| 2025-12 | 1 |
| 2026-01 | 5 |
| 2026-02 | 0 |
| 2026-03 | 3 |
| 2026-04 | 1 |
| 2026-05 | 3 |
| 2026-06 | 3 |
| 2026-07 | 9 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 41 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High27
- Medium8
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Ddk.
- CVE-2026-16280GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset9.8
- CVE-2026-49745GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 07.8
- CVE-2026-49744GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()7.8
- CVE-2026-49743GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed7.8
- CVE-2026-45203GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU7.8
- CVE-2026-45196GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel7.8
- CVE-2026-7639GPU DDK - Page UAF read in PMMETA_PROTECT heap memory7.8
- CVE-2026-41154GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse7.8
- CVE-2026-34196GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem7.8
- CVE-2026-45195GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted7.8
- CVE-2026-21734GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation7.7
- CVE-2026-34193GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()4.3
- CVE-2026-22166GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable8.1
- CVE-2026-22165GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/write of RMJob::apsCCBs8.1
- CVE-2026-22167GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrary write to physical memory7.8
Product grouping is registry-driven, with AI assist and human review. How it works