Guest VM Kernel Software Vulnerability in GPU Firmware by Imagination Technologies
CVE-2026-49744

7.8HIGH

Key Information:

Vendor
CVE Published:
24 July 2026

What is CVE-2026-49744?

A vulnerability exists in the kernel software of Guest Virtual Machines (VMs) that can cause improper commands to be sent to the GPU firmware. This may lead to out-of-bounds data writes, allowing malware introduced within a Guest Kernel Mode Driver (KMD) to perform actions that result in privilege escalation, thus potentially escaping the virtualization boundaries and compromising system integrity.

Affected Version(s)

Graphics DDK Linux 1.18 RTM2

Graphics DDK Linux 23.2 RTM2

Graphics DDK Linux 24.2 RTM2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.