CVE-2026-34194 PUBLISHED

GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count

Assigner: imaginationtech
Reserved: 26.03.2026 Published: 08.06.2026 Updated: 08.06.2026

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation.

The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled across buffers of different sizes.

Product Status

Vendor Imagination Technologies
Product Graphics DDK
Versions Default: unknown
  • Version 1.18 RTM is unaffected
  • Version 23.2 RTM is unaffected
  • Version 24.2 RTM is affected
  • affected from 25.1 RTM to 25.3 RTM (incl.)
  • Version 26.1 RTM is affected

References

Problem Types

  • CWE-468: Incorrect Pointer Scaling CWE

Impacts

  • CAPEC - CAPEC-123: Buffer Manipulation (Version 3.9)