7.8
CVE-2026-49745
- EPSS 0.11%
- Veröffentlicht 24.07.2026 09:16:24
- Zuletzt bearbeitet 12.08.2026 18:50:40
- Erkennungen
GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imaginationtech ≫ Ddk Version < 26.1
Imaginationtech ≫ Ddk Version 26.1 Update rtm1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.11% | 0.015 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-823 Use of Out-of-range Pointer Offset
The product performs pointer arithmetic on a valid pointer, but it uses an offset that can point outside of the intended range of valid memory locations for the resulting pointer.
https://www.imaginationtech.com/gpu-driver-vulnerabilities/