CVE-2026-34194CWE-468
GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count
High · published June 8, 2026
What it is
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation.
The product accidentally refers to the wrong memory due to the semantics of how math operations are implicitly scaled across buffers of different sizes.
The record
Technical detail
- CVSS v3.1
- 7.1 · HIGH
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- CVSS v4.0
- Not supplied
- EPSS
- 0.00116 · 1.8th percentile
- Weakness
- CWE-468 · Incorrect Pointer Scaling
- Published
- 2026-06-08T14:58Z
EPSS history
Timeline