« Volver al listado

CVE-2026-45202

Estado: AplazadaMedia (5.5)—

Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption.

Scenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-45202",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-45202",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-27T19:17:06.676810Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
      "affectedData": [
        {
          "vendor": "Imagination Technologies",
          "product": "Graphics DDK",
          "versions": [
            {
              "status": "affected",
              "version": "1.18 RTM2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "23.2 RTM2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "24.2 RTM2",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "25.1 RTM2",
              "versionType": "custom",
              "lessThanOrEqual": "25.3 RTM"
            },
            {
              "status": "affected",
              "version": "26.1 RTM1",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "26.1 RTM2",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux",
            "Android"
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2026-08-21T04:18:03.767",
  "references": [
    {
      "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities/",
      "source": "367425dc-4d06-4041-9650-c2dc6aaa27ce"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "367425dc-4d06-4041-9650-c2dc6aaa27ce",
      "description": [
        {
          "lang": "en",
          "value": "CWE-415"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Software installed and run as a non-privileged user may conduct GPU system calls which cause GPU memory leaks and possible kernel heap corruption.\n\n\n\nScenario caused by memory free paths not maintaining state data of upgraded higher order allocations. This could cause memory leak or double free event."
    }
  ],
  "lastModified": "2026-09-03T17:11:18.230",
  "sourceIdentifier": "367425dc-4d06-4041-9650-c2dc6aaa27ce"
}