Vulnerability Details CVE-2026-34193
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 4.1%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-34193
-
cpe:2.3:a:imaginationtech:ddk:-
-
cpe:2.3:a:imaginationtech:ddk:1.15
-
cpe:2.3:a:imaginationtech:ddk:1.17
-
cpe:2.3:a:imaginationtech:ddk:1.18
-
cpe:2.3:a:imaginationtech:ddk:23.2
-
cpe:2.3:a:imaginationtech:ddk:23.3
-
cpe:2.3:a:imaginationtech:ddk:24.1
-
cpe:2.3:a:imaginationtech:ddk:24.2
-
cpe:2.3:a:imaginationtech:ddk:24.3
-
cpe:2.3:a:imaginationtech:ddk:25.1
-
cpe:2.3:a:imaginationtech:ddk:25.2
-
cpe:2.3:a:imaginationtech:ddk:25.3
-
cpe:2.3:a:imaginationtech:ddk:26.1
-
cpe:2.3:o:google:android:-
-
cpe:2.3:o:linux:linux_kernel:-