CVE-2026-45199General

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-823

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-21: 3Technical Details · 2026-08-21: 308-21
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-45199 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU … https://www.cve.org/CVERecord?id=CVE-2026-45199

    Post summary

    The message announces CVE-2026-45199, noting that guest‑VM kernel software can issue malformed GPU firmware commands to write data outside its virtualised GPU memory, without providing any PoC, exploit code, or patch information.

    000101.0K
    58.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-45199 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU … https://www.cve.org/CVERecord?id=CVE-2026-45199 ----- Traducción: CVE-2026-45199 El … http://infoflow.cloud`

    Post summary

    The entry notes a kernel-level flaw where a guest VM can send malformed GPU firmware commands to cause out-of-bounds writes, but provides no PoC, exploit code, patch information or reports of active exploitation.

    0000032
    102 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-45199 Guest VM Kernel Privilege Escalation via Improper GPU Firmware Commands https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-45199

    Post summary

    The post announces a new CVE and provides a brief technical description, but offers no exploit details, PoC, patch, or evidence of active attacks.

    00000110
    4.1K followersView on X

Explore more