CVE Tools

Graphics Ddk

87 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Graphics Ddk, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

Graphics Ddk CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Graphics Ddk CVEs per month
MonthCVEs
2024-101
2024-113
2024-125
2025-0112
2025-024
2025-034
2025-043
2025-052
2025-064
2025-071
2025-083
2025-092
2025-100
2025-112
2025-121
2026-015
2026-020
2026-033
2026-041
2026-053
2026-0611
2026-079
2026-086
2026-092

Severity

How the 87 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical67%
  • High6271%
  • Medium1618%
  • Low33%

Latest CVEs

The 15 most recently published vulnerabilities affecting Graphics Ddk.

  1. CVE-2026-45197GPU DDK - TOCTOU affecting psFWMemContext->uiPageCatBaseRegSet2.5
  2. CVE-2026-45200GPU DDK - Double free in _FreeOSPages due to incorrect allocation flag set by _EncodeAllocationFlags7.8
  3. CVE-2026-45202GPU DDK - Silent High-Order CMA Memory Leak & Double Free in `_FreeOSPages_Fast`5.5
  4. CVE-2026-45201GPU DDK - Incorrect page size validation in PhysmemNewRamBackedPMR could lead to OOB read and/or write of arbitrary physical memory7.8
  5. CVE-2026-45199GPU DDK - rgxfw_to_ptr() does not reject FW private data pointers7.8
  6. CVE-2026-49746GPU DDK - Dimension Mismatch and Integer Truncation in PMRDevPhysAddrOSMem7.1
  7. CVE-2026-45204GPU DDK - Out of bounds memory access and kernel NULL pointer dereference in DmaTransfer when pui64Address is a pointer to device memory5.5
  8. CVE-2026-45198GPU DDK - RGXFWIF_SYSINIT::sCorememDataStore is untrusted7.8
  9. CVE-2026-16280GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset9.8
  10. CVE-2026-49745GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 07.8
  11. CVE-2026-49744GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()7.8
  12. CVE-2026-49743GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed7.8
  13. CVE-2026-45203GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU7.8
  14. CVE-2026-45196GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel7.8
  15. CVE-2026-7639GPU DDK - Page UAF read in PMMETA_PROTECT heap memory7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store