CVE-2026-34195

HIGH

GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexes

Title source: cna
STIX 2.1

Description

Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of bounds write in the kernel. The product incorrectly indexes internal state when performing sparse allocation remapping.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (6)
Imagination Technologies/Graphics DDK 1.18 RTM
Imagination Technologies/Graphics DDK 23.2 RTM
Imagination Technologies/Graphics DDK 24.2 RTM
Imagination Technologies/Graphics DDK 25.1 RTM - 25.3 RTM
Imagination Technologies/Graphics DDK 26.1 RTM
Imagination Technologies/Graphics DDK 26.2 RTM
Published Jun 12, 2026
Tracked Since Jun 13, 2026