TOCTOU Vulnerability in Guest VM Affecting GPU Firmware by Imagination Technologies
CVE-2026-45197

Currently unrated

Key Information:

Vendor
CVE Published:
4 September 2026

What is CVE-2026-45197?

A vulnerability exists within the GPU Firmware of Imagination Technologies which allows a Guest Virtual Machine (VM) to send improper commands that can result in unauthorized read and/or write operations outside the allocated memory space. This issue arises due to a Time-of-check to time-of-use (TOCTOU) flaw, where initial memory access checks may be bypassed after validation, leading to potential exploitation of memory resources. Such vulnerabilities can be particularly concerning in virtualized environments, as they may compromise the integrity and security of the Guest VM’s operations.

Affected Version(s)

Graphics DDK Linux 1.18 RTM2

Graphics DDK Linux 23.2 RTM2

Graphics DDK Linux 24.2 RTM2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.