GPU Firmware Vulnerability in Guest Virtual Machine Environments by Imagination Technologies
CVE-2026-45199

7.8HIGH

Key Information:

Vendor
CVE Published:
21 August 2026

What is CVE-2026-45199?

This vulnerability allows kernel software running inside a Guest Virtual Machine to issue improper commands to the GPU firmware, which can lead to unauthorized data writes outside the allocated virtualized GPU memory. Such commands can facilitate privilege escalation attacks, compromising the integrity and security of the entire virtualized environment.

Affected Version(s)

Graphics DDK Linux 1.18 RTM2

Graphics DDK Linux 23.2 RTM2

Graphics DDK Linux 24.2 RTM2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.