Vulnerability Description
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-45199?
CVE-2026-45199 is a documented vulnerability. Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and ...
How severe is CVE-2026-45199?
CVSS scoring is not yet available for CVE-2026-45199. Check NVD for updates.
Is there a patch for CVE-2026-45199?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.