CVE-2026-34194CWE-468

GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count

High · published June 8, 2026

CVSS v3.1
7.1
EPSS
0%
Percentile
1.8
In the wild
Unconfirmed
What it is

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation.

The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled across buffers of different sizes.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00116 · 1.8th percentile
Weakness
CWE-468 · Incorrect Pointer Scaling
Published
2026-06-08T14:58Z
EPSS history
Timeline
  • 08 JUN 14:58Z
    GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count
    cvelistv5