{"id":"CVE-2026-45200","title":"Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption.\n\n\n\nScenario caused by fabricating a spec…","summary":"Software installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption.\n\n\n\nScenario caused by fabricating a spec…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"Imagination Technologies","product":"Graphics DDK","affected":["graphics_ddk 24.2 RTM2","graphics_ddk >= 25.1 RTM2 <= 25.3 RTM","graphics_ddk 26.1 RTM1"],"published":"2026-09-04","updated":"2026-09-09","sourceUpdated":"2026-09-09T05:17:24.040","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45200","references":[{"url":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/","label":"367425dc-4d06-4041-9650-c2dc6aaa27ce"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-08T14:25:50.878445Z"},"epss":0.0011,"epssPercentile":0.01438,"ingestedAt":"2026-09-08T15:33:26.959Z","slug":"CVE-2026-45200","body":"## Overview\n\nSoftware installed and run as a non-privileged user may conduct improper GPU driver IOCTL calls to create an allocation scenario that when freed would cause double free and kernel heap corruption.\n\n\n\nScenario caused by fabricating a specific combination of flags on the allocation interface that would cause an incorrect double free event when freed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}