Description
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.
The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.
The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.
Published:
2026-09-04
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ |
|
History
Fri, 04 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory. The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated. | |
| Title | GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSet | |
| Weaknesses | CWE-367 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: imaginationtech
Published:
Updated: 2026-09-04T01:53:55.981Z
Reserved: 2026-05-11T10:58:04.162Z
Link: CVE-2026-45197
No data.
Status : Received
Published: 2026-09-04T02:17:19.003
Modified: 2026-09-04T02:17:19.003
Link: CVE-2026-45197
No data.
OpenCVE Enrichment
No data.
Weaknesses
