๐Ÿ” CVE Alert

CVE-2026-45199

UNKNOWN 0.0

GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.

CWE CWE-823
Vendor imagination technologies
Product graphics ddk
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for imagination technologies graphics ddk

Be the first to know when new unknown vulnerabilities affecting imagination technologies graphics ddk are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Imagination Technologies / Graphics DDK
1.18 RTM2 23.2 RTM2 24.2 RTM2 25.1 RTM2 โ‰ค 25.3 RTM

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
imaginationtech.com: https://www.imaginationtech.com/gpu-driver-vulnerabilities/