« Volver al listado

CVE-2026-45195

Estado: AnalizadaAlta (7.8)—

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel.

Addresses passed to the GPU Firmware can be used by the Firmware for more privileged memory accesses than are permitted by the system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:L, PR:L, UI:N indica escalada local de privilegios. GPU Firmware permite lecturas/escrituras de memoria fuera de rango, logrando acceso a datos protegidos e integridad del sistema.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45195",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-45195",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-26T19:14:26.787970Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
      "affectedData": [
        {
          "vendor": "Imagination Technologies",
          "product": "Graphics DDK",
          "versions": [
            {
              "status": "affected",
              "version": "1.18 RTM",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "23.2 RTM",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.2 RTM",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "25.1 RTM",
              "versionType": "custom",
              "lessThanOrEqual": "25.3 RTM"
            },
            {
              "status": "affected",
              "version": "26.1 RTM",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "26.2 RTM",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux",
            "Android"
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-06-26T16:16:30.893",
  "references": [
    {
      "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "367425dc-4d06-4041-9650-c2dc6aaa27ce"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
      "description": [
        {
          "lang": "en",
          "value": "CWE-280"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory read or write outside the permitted range of memory for the host kernel.\n\n\n\nAddresses passed to the GPU Firmware can be used by the Firmware for more privileged memory accesses than are permitted by the system."
    }
  ],
  "lastModified": "2026-06-29T18:44:21.100",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA5B5D24-BD0C-46D4-BBE4-4A983B0D7FDC",
              "versionEndIncluding": "25.3"
            },
            {
              "criteria": "cpe:2.3:a:imaginationtech:ddk:26.1:rtm1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6047F4B-B29A-44F7-8F80-8A53C1917F38"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "367425dc-4d06-4041-9650-c2dc6aaa27ce"
}