CVE-2026-49744: GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49744?
The severity of CVE-2026-49744 is rated as high with a CVSS score of 7.8.
What vulnerabilities does CVE-2026-49744 address?
CVE-2026-49744 addresses improper command execution and out-of-bounds memory access in the GPU Driver Development Kit.
How do I fix CVE-2026-49744?
To fix CVE-2026-49744, users should update to the latest version of the GPU DDK that mitigates this vulnerability.
What are the potential impacts of CVE-2026-49744?
CVE-2026-49744 may allow privilege escalation and unauthorized access to memory outside of the intended virtualized GPU environment.
Who is affected by CVE-2026-49744?
CVE-2026-49744 affects systems running the GPU Driver Development Kit within guest virtualized environments.