CVE-2026-21734: GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation

Published Jun 26, 2026
·
Updated

A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-bounds write crash in the GPU shader compiler library. On certain platforms, when the compiler process has system privileges this could enable further exploits on the device.

An edge case using a very small value in GPU shader code can cause a segmentation fault in the GPU shader compiler due to am out-of-bounds write.

Affected Software

3 affected components
GPU DDK libusc><=
Imaginationtech Ddk<=25.2
Imaginationtech Ddk=25.3-rtm

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Reduce or remove system privileges for the GPU compiler process on affected platforms to limit the impact of a GPU shader compiler crash (e.g., run the compiler under least-privilege instead of system privileges).

  2. Compensating control

    Validate/sanitize or block WebGPU shader code that includes unusually complex or malformed shader code before it is passed to the GPU compiler process to prevent triggering the out-of-bounds write crash in the GPU shader compiler library.

Event History

Jun 26, 2026
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-21734?

The risk rating for CVE-2026-21734 is 60, indicating a moderate severity level.

2

How do I fix CVE-2026-21734?

To address CVE-2026-21734, ensure that the GPU driver is updated to the latest version provided by the manufacturer.

3

What type of vulnerability is CVE-2026-21734?

CVE-2026-21734 is an out-of-bounds write vulnerability that can occur during WebGPU shader compilation.

4

Which software is affected by CVE-2026-21734?

CVE-2026-21734 specifically impacts the GPU DDK libusc related to GPU shader compilation.

5

Can CVE-2026-21734 lead to further exploits?

Yes, if exploited on certain platforms with system privileges, CVE-2026-21734 could potentially enable further exploits on the device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-21734 - GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation - SecAlerts