Junglewise Threat Intelligence

CVE-2026-45203: Imagination Technologies Graphics DDK TOCTOU in GPU Firmware command handling

CVE-2026-45203 · Severity: info · CVSS 0 · Published 2026-07-10

Technologies: Imagination Technologies Graphics DDK. Vendors: Imagination Technologies.

Executive brief

A vulnerability in the Imagination Technologies Graphics DDK (Driver Development Kit) allows malicious software running within a virtual machine to bypass memory protections. By exploiting a timing flaw in how the GPU firmware validates commands, an attacker can force the system to write data to unauthorized memory locations. This could lead to a compromise of the host kernel, potentially allowing an attacker to escape a virtual machine or gain elevated control over the entire system.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the Imagination Technologies Graphics DDK. Kernel software running within a guest VM can post commands to the GPU firmware; a malicious driver can modify command values in memory after the firmware has validated them but before they are executed. This allows the attacker to trigger memory writes outside the permitted range of the host kernel. The vulnerability affects multiple versions of the Graphics DDK on Linux and Android platforms and is addressed in version 26.1 RTM2.

Affected products

  • Imagination Technologies Graphics DDK 1.18 RTM2, 23.2 RTM2, 24.2 RTM2, 25.1 RTM2 to 25.3 RTM, 26.1 RTM1

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats