CVE-2026-49744 PUBLISHED

GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()

Assigner: imaginationtech
Reserved: 01.06.2026 Published: 24.07.2026 Updated: 24.07.2026

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.

Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.

Product Status

Vendor Imagination Technologies
Product Graphics DDK
Versions Default: unknown
  • Version 1.18 RTM2 is affected
  • Version 23.2 RTM2 is affected
  • Version 24.2 RTM2 is affected
  • affected from 25.1 RTM2 to 25.3 RTM (incl.)
  • Version 26.1 RTM1 is unaffected

References

Problem Types

  • CWE - CWE-823: Use of Out-of-range Pointer Offset (4.16) CWE

Impacts

  • CAPEC - CAPEC-480: Escaping Virtualization (Version 3.9)