Junglewise Threat Intelligence

CVE-2026-45197: Imagination GPU Firmware TOCTOU vulnerability in memory access validation

CVE-2026-45197 · Severity: low · CVSS 2.5 · Published 2026-09-04

Vendors: Imagination Technologies.

Executive brief

Imagination Technologies GPU firmware contains a time-of-check-time-of-use (TOCTOU) vulnerability that allows a Guest VM to bypass memory access restrictions. A malicious guest kernel could issue improper GPU commands to read or write data outside its allocated virtual GPU memory, potentially accessing sensitive information or corrupting GPU memory belonging to other virtual machines or the host.

Technical details

This vulnerability is a time-of-check-time-of-use (TOCTOU) race condition in the Imagination GPU Firmware. The firmware validates memory access parameters provided by a Guest VM kernel before using them to configure GPU memory accesses; however, insufficient synchronization between the validation check and the actual use of these parameters allows an attacker to modify the parameters after validation but before use. An attacker with kernel-level code execution in a Guest VM can exploit this to post improper commands to the GPU, triggering unauthorized reads or writes to GPU memory outside the Guest's virtualized allocation. This requires local access to the Guest VM and the ability to execute kernel-level code. Patches are available from Imagination Technologies.

Affected products

  • Imagination Technologies GPU Firmware <UNKNOWN>

Timeline

  • 2026-09-04: disclosed

References