CVE-2026-34193: GPU DDK - Arbitrary write via UFO updates due insufficient pointer validation in rgxfw_to_ptr()
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address translation allowed a compromised Host (Kernel) to perform arbitrary writes to firmware memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34193?
The severity of CVE-2026-34193 is rated as medium with a CVSS score of 4.3.
How do I fix CVE-2026-34193?
To fix CVE-2026-34193, ensure that your GPU DDK is updated to the patched version released by the vendor.
What risks are associated with CVE-2026-34193?
CVE-2026-34193 poses a risk of arbitrary write operations, potentially allowing a compromised host kernel to manipulate GPU firmware.
What systems are affected by CVE-2026-34193?
CVE-2026-34193 affects systems running the GPU DDK that utilizes address translation in the guest/host VM environments.
Who is responsible for addressing CVE-2026-34193?
The responsibility for addressing CVE-2026-34193 lies with the vendor providing the GPU DDK, requiring users to apply relevant security updates.