CVE-2026-34193: Imaginationtech Ddk

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory. A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.

Affected products

Published 2026-06-01. Last modified 2026-08-12.