CVE-2026-34193

EUVD-2026-33627
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.



A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 3.9%
Affected Products (NVD)
VendorProductVersion
imaginationtechddk
𝑥
< 26.1
imaginationtechddk
26.1:rtm1
𝑥
= Vulnerable software versions