PT-2026-68842 · Gpu Ddk · Gpu Ddk
CVE-2026-45198
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GPU DDK (affected versions not specified)
Description
Kernel software from a non-secure operating system on a platform with Trusted Execution Environment (TEE) support may cause GPU Firmware to boot using data from non-secure memory. The GPU thread of control (Firmware) utilizes a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory and main memory. An attacker with control over the REE kernel can modify the pointer value, leading to the corruption of data used by the GPU Firmware. This issue occurs within the
RGXFWIF SYSINIT::sCorememDataStore function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gpu Ddk