CVE-2026-45203: Imaginationtech Ddk

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.

Affected products

Published 2026-07-10. Last modified 2026-08-12.