Description
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
Published:
2026-07-24
Score:
n/a
EPSS:
< 1% Very Low
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ |
|
History
Mon, 27 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Imaginationtech
Imaginationtech graphics Ddk |
|
| Vendors & Products |
Imaginationtech
Imaginationtech graphics Ddk |
Fri, 24 Jul 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries. | |
| Title | GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex() | |
| Weaknesses | CWE-823 | |
| References |
|
Status: PUBLISHED
Assigner: imaginationtech
Published:
Updated: 2026-07-24T17:25:55.652Z
Reserved: 2026-06-01T11:03:13.032Z
Link: CVE-2026-49744
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T05:45:03Z
Weaknesses
-
CWE-823
Use of Out-of-range Pointer Offset