CVE-2026-34196

7.8

Imagination · Graphics DDK

A use-after-free vulnerability in Imagination Graphics DDK allows a local low-privileged user to conduct improper GPU system calls leading to arbitrary read and write access.

Executive summary

An integer overflow and use-after-free vulnerability in the Imagination Technologies Graphics DDK allows local, low-privileged users to achieve high confidentiality, integrity, and availability impact.

Vulnerability

This vulnerability is a use-after-free flaw (CWE-416) triggered via improper GPU system calls by a locally authenticated user with low privileges.

Business impact

A successful exploit of this vulnerability could allow a malicious local user to gain complete control over the affected system, resulting in total data compromise, system instability, and unauthorized access. With a CVSS score of 7.8 (High), the risk profile is elevated because local attackers can leverage the flaw to escalate privileges or corrupt memory.

Remediation

Immediate Action: Update the Imagination Technologies Graphics DDK to version 26.1 RTM2 or later.

Proactive Monitoring: Monitor system logs for unusual local process activity, GPU driver crashes, or unauthorized attempts to interact with graphics device nodes.

Compensating Controls: Restrict local user access and interactive logon rights to trusted personnel only, reducing the attack surface for locally executed code.

Exploitation status

Public Exploit Available: No (false)

Analyst recommendation

Given the high CVSS severity and the potential for total system compromise, administrators should prioritize updating the Imagination Graphics DDK across all affected systems. Applying the vendor-provided patch is critical to neutralizing the use-after-free vector and protecting host integrity.

More Imagination CVEs

Sources