CVE-2026-34192: Imagination Technologies Graphics Ddk
High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading to UAF of GPU page tables. The vulnerability allows physical memory allocated for MMU page tables to be used after being freed. This was caused by an error path that would not cleanup properly before freeing the physical allocation.
Affected products
- Imagination Technologies Graphics Ddk: version 1.18 RTM only; version 23.2 RTM only; version 24.2 RTM only; from 25.1 RTM, up to and including 25.3 RTM
Published 2026-06-19. Last modified 2026-06-22.