CVE-2026-45197CWE-367

CVE-2026-45197

published September 4, 2026

CVSS
EPSS
0%
Percentile
1.5
In the wild
Unconfirmed
What it is

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read and/or write data outside the Guest's virtualised GPU memory.

The firmware uses data provided by the Guest VM to set up accesses to memory. It validated this before use, but a TOCTOU bug was present which allowed the earlier check results to be invalidated.

The record
Technical detail
CVSS
Not scored
CVSS v4.0
Not supplied
EPSS
0.00112 · 1.5th percentile
Weakness
CWE-367 · Time-of-check Time-of-use (TOCTOU) Race Condition
Published
2026-09-04T06:17Z
References (1)
EPSS history
Timeline
  • 05 SEP 03:42Z
    EPSS moved — → 0%
    epss
  • 04 SEP 01:53Z
    GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSet
    cvelistv5