Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
History

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech graphics Ddk
Vendors & Products Imaginationtech
Imaginationtech graphics Ddk

Fri, 21 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Description Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
Title GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
Weaknesses CWE-823
References

cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published: 2026-08-21T03:36:39.887Z

Updated: 2026-08-26T18:59:52.011Z

Reserved: 2026-05-11T10:58:04.162Z

Link: CVE-2026-45199

cve-icon Vulnrichment

Updated: 2026-08-26T18:59:47.211Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T04:18:02.650

Modified: 2026-09-03T17:11:18.230

Link: CVE-2026-45199

cve-icon Redhat

No data.