TOCTOU Vulnerability in Guest VM Affecting GPU Firmware by Imagination Technologies
CVE-2026-45197
Currently unrated
What is CVE-2026-45197?
A vulnerability exists within the GPU Firmware of Imagination Technologies which allows a Guest Virtual Machine (VM) to send improper commands that can result in unauthorized read and/or write operations outside the allocated memory space. This issue arises due to a Time-of-check to time-of-use (TOCTOU) flaw, where initial memory access checks may be bypassed after validation, leading to potential exploitation of memory resources. Such vulnerabilities can be particularly concerning in virtualized environments, as they may compromise the integrity and security of the Guest VM’s operations.
Affected Version(s)
Graphics DDK Linux 1.18 RTM2
Graphics DDK Linux 23.2 RTM2
Graphics DDK Linux 24.2 RTM2
