安装在客户机虚拟机(Guest VM)内部并正在运行的内核软件,可能向 GPU 固件发送不正确的命令,从而触发对客户机虚拟化 GPU 内存范围之外的数据进行写入。 在客户机虚拟机内部安装并运行的软件可以向 GPU 发送命令,导致越界内存访问。攻击者可以利用此类越界访问实现权限提升。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Imagination Technologies | Graphics DDK | 1.18 RTM2 |
affected |
23.2 RTM2 |
affected | ||
24.2 RTM2 |
affected | ||
25.1 RTM2≤ 25.3 RTM |
affected | ||
26.1 RTM1 |
unaffected | ||
26.1 RTM2 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Imagination Technologies | Graphics DDK | 1.18 RTM2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45202 | GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast` | |
| CVE-2026-45201 | GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read |
No comments yet