CVE-2026-45203: Imaginationtech Ddk
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.
Affected products
- Imaginationtech Ddk: before 26.1 (fixed in 26.1); version 26.1 only
Published 2026-07-10. Last modified 2026-08-12.