Vulnerability Details CVE-2026-49744
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 1.5%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-49744
-
cpe:2.3:a:imaginationtech:ddk:-
-
cpe:2.3:a:imaginationtech:ddk:1.15
-
cpe:2.3:a:imaginationtech:ddk:1.17
-
cpe:2.3:a:imaginationtech:ddk:1.18
-
cpe:2.3:a:imaginationtech:ddk:23.2
-
cpe:2.3:a:imaginationtech:ddk:23.3
-
cpe:2.3:a:imaginationtech:ddk:24.1
-
cpe:2.3:a:imaginationtech:ddk:24.2
-
cpe:2.3:a:imaginationtech:ddk:24.3
-
cpe:2.3:a:imaginationtech:ddk:25.1
-
cpe:2.3:a:imaginationtech:ddk:25.2
-
cpe:2.3:a:imaginationtech:ddk:25.3
-
cpe:2.3:a:imaginationtech:ddk:26.1
-
cpe:2.3:o:google:android:-
-
cpe:2.3:o:linux:linux_kernel:-