CVE-2026-34193 PUBLISHED

GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()

Assigner: imaginationtech
Reserved: 26.03.2026 Published: 01.06.2026 Updated: 01.06.2026

Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.

A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.

Product Status

Vendor Imagination Technologies
Product Graphics DDK
Versions Default: unknown
  • Version 1.18 RTM is affected
  • Version 23.2 RTM is affected
  • Version 24.2 RTM is affected
  • affected from 25.1 RTM to 25.3 RTM (incl.)
  • Version 26.1 RTM1 is affected
  • Version 26.1 RTM2 is unaffected

References

Problem Types

  • CWE - CWE-823: Use of Out-of-range Pointer Offset (4.16) CWE

Impacts

  • CAPEC-129: Pointer Manipulation