CVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory.
The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory to main memory. An attacker with control over the REE kernel may modify the pointer value, corrupting the data used by the GPU Firmware.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-45198
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-45198 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Kernel software from
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…nvd · 2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…nvd · 2026-08-07
- highCVE-2026-49745: Kernel software installed and running inside a Guest VM may post improper commands to the GPU …nvd · 2026-07-24
- highCVE-2026-49744: Kernel software installed and running inside a Guest VM may post improper commands to the GPU …nvd · 2026-07-24
- highCVE-2026-49743: Software installed and run as a non-privileged user may conduct improper GPU system calls to m…nvd · 2026-07-24
- unknownCVE-2026-64022: In the Linux kernel, the following vulnerability has been resolved: gpio: aggregator: remove t…nvd · 2026-07-19
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07
- criticalCVE-2026-70332: Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attac…2026-08-07