{"id":"CVE-2026-45197","title":"Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.\n\n\n\nThe firmware uses data provided by the Guest VM to …","summary":"Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.\n\n\n\nThe firmware uses data provided by the Guest VM to …","severity":"low","cvss":2.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-367"],"vendor":"Imagination Technologies","product":"Graphics DDK","affected":["graphics_ddk 1.18 RTM2","graphics_ddk 23.2 RTM2","graphics_ddk 24.2 RTM2","graphics_ddk >= 25.1 RTM2 <= 25.3 RTM","graphics_ddk 26.1 RTM1"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T15:28:33.090","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45197","references":[{"url":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/","label":"367425dc-4d06-4041-9650-c2dc6aaa27ce"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T14:29:12.602426Z"},"epss":0.00069,"epssPercentile":0.00044,"ingestedAt":"2026-09-08T15:33:26.959Z","slug":"CVE-2026-45197","body":"## Overview\n\nKernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.\n\n\n\nThe firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}