SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-45203

HIGH · CVSS 7.8 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

A vulnerability exists in kernel software running within a Host VM, allowing a malicious driver to exploit a time-of-check to time-of-use (TOCTOU) bug. This flaw enables the driver to issue improper commands to the GPU firmware, potentially leading to unauthorized memory writes outside the host kernel's permitted range. Organizations utilizing virtualized environments with GPU resources should prioritize addressing this high-severity issue to mitigate risks of memory corruption and potential system compromise.

CVE
CVE-2026-45203
Severity
HIGH
CVSS
7.8
EPSS
0.09%

Original NVD Description

Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in memory after firmware validation but before use.