What is CVE-2026-49745?
CVE-2026-49745 is a vulnerability where kernel software in a Guest VM can send improper commands to the GPU Firmware, causing out-of-bounds writes beyond the guest's virtualized GPU memory. This may compromise the host system; applying security patches for the affected hypervisor is strongly recommended.
Azərbaycanca: CVE-2026-49745, qonaq VM-də işləyən kernel proqram təminatının GPU Firmware-a səhv əmrlər göndərərək virtual GPU yaddaşından kənara verilən yazmasına imkan verən boşluqdur. Bu, host sistemində məlumat sızması və ya imtiyaz artırılması riski yaradır; dərhal müvafiq VM monitor (hypervisor) yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
How can CVE-2026-49745 be exploited?
The kernel software in the Guest VM sends improper commands to the GPU Firmware, causing out-of-bounds writes beyond the guest's virtualized GPU memory. This may lead to data leakage or privilege escalation on the host system.
How to protect against CVE-2026-49745?
To protect against this vulnerability, it is strongly recommended to urgently apply the relevant hypervisor security patches.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.