Junglewise Threat Intelligence

CVE-2026-45199: Imagination GPU DDK improper memory access from guest VM

CVE-2026-45199 · Severity: high · CVSS 7.8 · Published 2026-08-21

Technologies: Imagination Technologies GPU DDK. Vendors: Imagination Technologies.

Executive brief

Imagination Technologies GPU drivers contain a vulnerability allowing guest virtual machines to send improper commands to GPU firmware, resulting in out-of-bounds memory writes. An attacker running software in a guest VM could exploit this to escalate privileges or potentially access data outside the intended GPU memory boundary, affecting virtualized systems using Imagination GPUs.

Technical details

The vulnerability exists in Imagination Technologies GPU DDK (Driver Development Kit) where guest VM software can post improperly crafted commands to GPU firmware. These malformed commands cause the GPU to perform out-of-bounds memory writes to locations outside the guest's virtualized GPU memory space. The attack requires only software execution within a guest VM context (unprivileged) and does not require network access. By exploiting this out-of-bounds write capability, an attacker can achieve privilege escalation or data access beyond their intended isolation boundary. The vulnerability affects GPU DDK releases up to and including version 25.2 RTM; patches are available in later releases.

Affected products

  • Imagination Technologies GPU DDK up to and including 25.2 RTM

Timeline

  • 2026-08-21: disclosed
  • other: CVE-2026-45199 published

References

Related threats