CVE-2026-49744
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.11%
- CWE
- CWE-823
- Published
- 2026-07-24
- Last modified
- 2026-07-24
Affected products
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
- Imagination Technologies Graphics DDK
Weakness type
Related vulnerabilities
- CVE-2026-31912 — OOBR in libpcap before 1.10.7
- CVE-2026-45199 — GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
- CVE-2026-72642 — Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process
- CVE-2026-49746 — GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem
- CVE-2026-49745 — GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0
- CVE-2026-21734 — GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation
- CVE-2026-34193 — GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()
- CVE-2026-28764 — MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability