CVE-2026-49744
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside th
CVSS
7.8
Alto
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Publicado: 24 jul 2026 · Última mod.: 24 jul 2026 · CWE-823
0.1%EPSS · 30 días0.1%
2026-07-242026-07-26
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-497457.8 ALT1.5%
——0Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory.
Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.3dCVE-2026-122908.1 ALT32.4%
——10Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.13dCVE-2026-462449.1 CRÍ24.5%
——7In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_inner: Fix IPv6 inner_thoff desync
In nft_inner_parse_l2l3(), when processing inner IPv6 packets,
ipv6_find_hdr() correctly computes the transport header offset
traversing all extension headers, but the result is immediately
overwritten with nhoff + sizeof(_ip6h) (40 bytes), which only
accounts for the IPv6 base header. This creates a desync between
inner_thoff (wrong — points to extension header start) and l4proto
(correct — e.g., IPPROTO_TCP), enabling transport header forgery
and potential firewall bypass. This issue affects stable versions
from Linux 6.2.
For comparison, the normal (non-inner) IPv6 path correctly
preserves ipv6_find_hdr()'s result. Removing the incorrect overwrite
ensures that ipv6_find_hdr()'s calculated transport header offset is
preserved, thereby fixing the desynchronization.5dCVE-2026-341934.3 MED4.0%
——1Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.6dCVE-2026-287647.8 ALT10.5%
——3MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability5dCVE-2026-46937.5 ALT48.9%
——15Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.13d