CVE-2026-45199CWE-823

CVE-2026-45199

High · published August 21, 2026

CVSS v3.1
7.8
EPSS
0%
Percentile
1.9
In the wild
Unconfirmed
What it is

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.

The record
Technical detail
CVSS v3.1
7.8 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00118 · 1.9th percentile
Weakness
CWE-823 · Use of Out-of-range Pointer Offset
Published
2026-08-21T08:18Z
References (1)
EPSS history
Timeline
  • 21 AUG 03:36Z
    GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers
    cvelistv5