CVE-2026-34195 Details
Description
Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause out of bounds write in the kernel. The product incorrectly indexes internal state when performing sparse allocation remapping.
A vulnerability has been identified in the Imagination Technologies GPU Driver Development Kit (DDK) that allows software running as a non-privileged user to exploit the GPU sparse memory API. This exploitation can lead to out-of-bounds writes in the kernel by causing improper management of memory allocations. The issue arises from incorrect indexing of internal states during sparse allocation remapping, which can be manipulated to write data outside the intended memory boundaries.
The DDK kernel module has been updated to address this vulnerability by correcting the management of sparse memory allocations and preventing out-of-bounds writes. Users should upgrade to the latest version of the GPU DDK that includes this fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| Imagination Technologies GPU DDK | <= 25.2 RTM <= 25.3 RTM >= 24.1, <= 25.3 RTM >= 24.2 RTM2, <= 26.1 RTM1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | imaginationtech |
Volerion