CVE-2026-45198
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main memory. An attacker with control over the REE kernel may modify the pointer value, corrupting the data used by the GPU Firmware.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.12%
- CWE
- CWE-822
- Published
- 2026-08-07
- Last modified
- 2026-08-07
Affected products
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
Weakness type
Related vulnerabilities
- CVE-2026-83498 — Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
- CVE-2026-83939 — Windows Secure Kernel Mode Elevation of Privilege Vulnerability
- CVE-2026-78451 — Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability
- CVE-2026-78444 — Microsoft Failover Cluster Remote Code Execution Vulnerability
- CVE-2026-72938 — Microsoft Office PowerPoint Information Disclosure Vulnerability
- CVE-2026-72956 — Microsoft Office PowerPoint Information Disclosure Vulnerability
- CVE-2026-69874 — Windows ALPC Elevation of Privilege Vulnerability
- CVE-2026-69900 — Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability