Improper Commands via Kernel Software Affecting GPU Firmware by Imagination Technologies
CVE-2026-45195

7.8HIGH

Key Information:

Vendor
CVE Published:
26 June 2026

What is CVE-2026-45195?

A security issue has been identified in the GPU Firmware of Imagination Technologies' products where kernel software running in a Host VM can send improper commands. This flaw may allow the firmware to perform unauthorized memory reads or writes, exceeding the defined permissions for the host kernel, potentially leading to exploitation and unauthorized access to sensitive system memory.

Affected Version(s)

Graphics DDK Linux 1.18 RTM

Graphics DDK Linux 23.2 RTM

Graphics DDK Linux 24.2 RTM

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.