# CVE-2026-34193

## Summary

- **CVE ID:** CVE-2026-34193
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **CWE:** CWE-823
- **Published:** Jun 1, 2026
- **Last Modified:** Jun 1, 2026

## Description

Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.



A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.

## Affected Products

- Imagination Technologies — Graphics DDK (1.18 RTM)
- Imagination Technologies — Graphics DDK (23.2 RTM)
- Imagination Technologies — Graphics DDK (24.2 RTM)
- Imagination Technologies — Graphics DDK (25.1 RTM)
- Imagination Technologies — Graphics DDK (26.1 RTM1)
- Imagination Technologies — Graphics DDK (26.1 RTM2)

## References

- [CNA](https://www.imaginationtech.com/gpu-driver-vulnerabilities/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.14%
- **EPSS Percentile:** 3.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._