7.8
CVE-2026-49744
- EPSS 0.11%
- Veröffentlicht 24.07.2026 09:16:24
- Zuletzt bearbeitet 12.08.2026 18:50:22
- Erkennungen
GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imaginationtech ≫ Ddk Version < 26.1
Imaginationtech ≫ Ddk Version 26.1 Update rtm1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.015 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-823 Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
https://www.imaginationtech.com/gpu-driver-vulnerabilities/