CVE-2026-45203
7.8Imagination Technologies · Graphics DDK
A Time-of-Check Time-of-Use race condition in the Imagination Graphics DDK allows a local authenticated attacker to achieve high privileges.
Executive summary
A time-of-check time-of-use race condition vulnerability in Imagination Technologies Graphics DDK allows a low-privileged local user to compromise host kernel memory and achieve total system impact.
Vulnerability
This is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability (CWE-367) occurring within the GPU firmware interaction handling. An authenticated local attacker requires low privileges and no user interaction to trigger the flaw by modifying values in memory after firmware validation but before use.
Business impact
A successful exploit allows a malicious driver running inside a Host VM to post improper commands to the GPU firmware, resulting in out-of-bounds memory writes in the host kernel. This can lead to total system compromise, data confidentiality breaches, integrity loss, and severe downtime. The CVSS score of 7.8 reflects a high severity level due to the complete compromise of the host kernel scope.
Remediation
Immediate Action: Update the Imagination Technologies Graphics DDK to version 26.1 RTM2 or later where the TOCTOU race condition is resolved.
Proactive Monitoring: Monitor host system logs for unexpected kernel crashes, anomalous driver behavior, or unauthorized resource access attempts within virtual machines.
Compensating Controls: Restrict local user access and virtual machine privileges to minimize the pool of actors capable of executing low-privileged kernel interactions.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Security teams must prioritize updating the Imagination Technologies Graphics DDK to version 26.1 RTM2 or later. Given the potential for total host kernel compromise, applying the vendor patch immediately is critical to eliminate local privilege escalation and memory corruption risks.