VYPR
High severity7.1NVD Advisory· Published Jun 8, 2026· Updated Jun 8, 2026

CVE-2026-34194

CVE-2026-34194

Description

Imagination GPU DDK driver vulnerability allows non-privileged users to trigger a use-after-free, potentially leading to system compromise.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Imagination GPU DDK driver vulnerability allows non-privileged users to trigger a use-after-free, potentially leading to system compromise.

Vulnerability

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting, creating a potential use-after-free scenario. This vulnerability affects DDK Releases up to and including 25.2 RTM [1]. The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled across buffers of different sizes.

Exploitation

An attacker running as a non-privileged user can trigger this vulnerability by making improper GPU system calls. The specific sequence involves exploiting the mismanagement of a mapping state maintained for a sparse memory allocation, leading to the incorrect referencing of memory across buffers of different sizes [1].

Impact

Successful exploitation of this vulnerability can lead to a use-after-free condition. This could allow an attacker to gain elevated privileges or potentially achieve arbitrary code execution on the affected system, depending on the specific context and available system resources [1].

Mitigation

The DDK kernel module has been updated to address this improper use of GPU system calls to ensure that resources cannot prematurely free whilst references exist. DDK Releases up to and including 25.2 RTM are affected. The DDK has been updated to introduce protection to prevent this information leak from taking place [1].

AI Insight generated on Jun 8, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.