CVE-2026-49745
EUVD-2026-4853424.07.2026, 09:16
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| imaginationtech | ddk | 𝑥 < 26.1 |
| imaginationtech | ddk | 26.1:rtm1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration