Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel.
A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.
References
| Link | Resource |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-10 21:16
Updated : 2026-08-12 17:34
NVD link : CVE-2026-45203
Mitre link : CVE-2026-45203
CVE.ORG link : CVE-2026-45203
JSON object : View
Products Affected
linux
- linux_kernel
imaginationtech
- ddk
- android
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
