Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.
The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.
The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ |
|
History
Fri, 04 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Imaginationtech
Imaginationtech graphics Ddk |
|
| Vendors & Products |
Imaginationtech
Imaginationtech graphics Ddk |
Fri, 04 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory. The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated. | |
| Title | GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSet | |
| Weaknesses | CWE-367 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: imaginationtech
Published:
Updated: 2026-09-04T01:53:55.981Z
Reserved: 2026-05-11T10:58:04.162Z
Link: CVE-2026-45197
No data.
Status : Received
Published: 2026-09-04T02:17:19.003
Modified: 2026-09-04T02:17:19.003
Link: CVE-2026-45197
No data.
OpenCVE Enrichment
Updated: 2026-09-04T15:15:14Z
Weaknesses