Vulnerability Details CVE-2026-45203
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel.
A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 0.6%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-45203
-
cpe:2.3:a:imaginationtech:ddk:-
-
cpe:2.3:a:imaginationtech:ddk:1.15
-
cpe:2.3:a:imaginationtech:ddk:1.17
-
cpe:2.3:a:imaginationtech:ddk:1.18
-
cpe:2.3:a:imaginationtech:ddk:23.2
-
cpe:2.3:a:imaginationtech:ddk:23.3
-
cpe:2.3:a:imaginationtech:ddk:24.1
-
cpe:2.3:a:imaginationtech:ddk:24.2
-
cpe:2.3:a:imaginationtech:ddk:24.3
-
cpe:2.3:a:imaginationtech:ddk:25.1
-
cpe:2.3:a:imaginationtech:ddk:25.2
-
cpe:2.3:a:imaginationtech:ddk:25.3
-
cpe:2.3:a:imaginationtech:ddk:26.1
-
cpe:2.3:o:google:android:-
-
cpe:2.3:o:linux:linux_kernel:-