CVE-2026-45196: GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel
Published Jul 10, 2026
·Updated
Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.
Affected Software
5 affected components
GPU DDK
All of the following
Any of the following
Imaginationtech Ddk<26.1
Imaginationtech Ddk=26.1-rtm1
Any of the following
Google Android
Linux Linux kernel
Event History
Jul 10, 2026
CVE Published
via MITRE·08:53 PM
Data Sourced
via MITRE·08:53 PM
DescriptionWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-45196?
CVE-2026-45196 has a risk rating of 54, indicating a moderate severity level.
2
How do I fix CVE-2026-45196?
To fix CVE-2026-45196, ensure that you update the GPU DDK to the latest patched version provided by the vendor.
3
What impacts does CVE-2026-45196 have on system security?
CVE-2026-45196 can lead to privilege escalation by allowing unauthorized access to GPU registers.
4
Who is affected by CVE-2026-45196?
CVE-2026-45196 affects systems using the GPU DDK with kernel software running in a Host VM.
5
What causes the vulnerability in CVE-2026-45196?
The vulnerability in CVE-2026-45196 is caused by unsanitized pointers from the host kernel that allow arbitrary GPU register writes.