nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-45198 CVE-2026-45198
HIGH
GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted
Record summary
CVE-2026-45198 has a selected CVSS score of 7.8 (high).
Description
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main memory. An attacker with control over the REE kernel may modify the pointer value, corrupting the data used by the GPU Firmware.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 7, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Graphics DDKBrowse Imagination Technologies / Graphics DDKDefault status: unknown | CVE List | 1.17 RTM2 | affected |
| 1.18 RTM2 | affected | ||
| 23.2 RTM2 | affected | ||
| 24.2 RTM2 | affected | ||
| 25.1 RTM2 to ≤ 25.3 RTM | affected | ||
| 26.1 RTM1 | affected | ||
| 26.1 RTM2 | unaffected |
References
2imaginationtech.com
https://www.imaginationtech.com/gpu-driver-vulnerabilities