---
id: CVE-2026-45203
title: >-
  Kernel software installed and running inside a Host VM may post improper
  commands to the GPU Firmware to trigger a memory write outside the permitted
  range of memory for the host kernel.




  A TOCTOU bug existed where a malicious driver c…
summary: >-
  Kernel software installed and running inside a Host VM may post improper
  commands to the GPU Firmware to trigger a memory write outside the permitted
  range of memory for the host kernel.




  A TOCTOU bug existed where a malicious driver c…
severity: none
cwe:
  - CWE-367
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45203'
references:
  - url: 'https://www.imaginationtech.com/gpu-driver-vulnerabilities/'
    label: 367425dc-4d06-4041-9650-c2dc6aaa27ce
tags:
  - nvd
epss: 0.00125
epssPercentile: 0.02524
ingestedAt: '2026-07-11T20:15:26.874Z'
---

## Overview

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel.



A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
