PT-2026-68842 · Gpu Ddk · Gpu Ddk

CVE-2026-45198

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GPU DDK (affected versions not specified)
Description Kernel software from a non-secure operating system on a platform with Trusted Execution Environment (TEE) support may cause GPU Firmware to boot using data from non-secure memory. The GPU thread of control (Firmware) utilizes a pointer from non-secure memory belonging to the Rich Execution Environment (REE) when saving or retrieving internal data between the tightly coupled private memory and main memory. An attacker with control over the REE kernel can modify the pointer value, leading to the corruption of data used by the GPU Firmware. This issue occurs within the RGXFWIF SYSINIT::sCorememDataStore function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45198

Affected Products

Gpu Ddk