VYPR

GPU Firmware

by Imagination Technologies

CVEs (21)

  • CVE-2025-0467HigApr 18, 2025
    risk 0.53cvss 8.2epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2026-45199HigAug 21, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds…

  • CVE-2026-45198HigAug 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software from a non-secure operating system on a platform with Trusted Execution Environment support, may cause GPU Firmware to boot up using data from non-secure memory. The GPU thread of control (Firmware) uses a pointer from non-secure memory belonging to the Rich…

  • CVE-2026-49745HigJul 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds…

  • CVE-2026-49744HigJul 24, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation…

  • CVE-2026-45203HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memory write outside the permitted range of memory for the host kernel. A TOCTOU bug existed where a malicious driver could modify values in memory after…

  • CVE-2026-45196HigJul 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU register access which can lead to privilege escalation.

  • CVE-2024-52939HigFeb 22, 2025
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write data outside the Guest's virtualised GPU memory.

  • CVE-2024-46975HigFeb 22, 2025
    risk 0.51cvss 7.9epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data into another Guest's virtualised GPU memory.

  • CVE-2024-52938HigJan 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to subvert reconstruction activities to trigger a write of data outside the Guest's virtualised GPU memory.

  • CVE-2025-58407HigNov 17, 2025
    risk 0.48cvss 7.4epss 0.00

    Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.

  • CVE-2024-12577HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2024-47895HigJan 13, 2025
    risk 0.46cvss 7.1epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.

  • CVE-2024-47894HigJan 13, 2025
    risk 0.46cvss 7.1epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU memory.

  • CVE-2024-52937MedJan 13, 2025
    risk 0.44cvss 6.7epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2024-47893MedMay 17, 2025
    risk 0.42cvss 6.5epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to read and/or write data outside the Guest's virtualised GPU memory.

  • CVE-2024-52936MedJan 13, 2025
    risk 0.29cvss 4.4epss 0.00

    Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2026-34193MedJun 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to…

  • CVE-2024-52935MedJan 13, 2025
    risk 0.27cvss 4.1epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

  • CVE-2024-47896LowFeb 22, 2025
    risk 0.21cvss 3.3epss 0.00

    Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

Page 1 of 2