Search
Search Results (10 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-58408 | 1 Imaginationtech | 1 Graphics Ddk | 2025-12-01 | 5.9 Medium |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free. The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use. | ||||
| CVE-2025-58410 | 1 Imaginationtech | 1 Graphics Ddk | 2025-11-18 | 7.5 High |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only. This is caused by improper handling of the memory protections for the buffer resource. | ||||
| CVE-2025-58407 | 1 Imaginationtech | 1 Graphics Ddk | 2025-11-18 | 7.4 High |
| Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine. | ||||
| CVE-2025-46709 | 1 Imaginationtech | 2 Ddk, Graphics Ddk | 2025-10-17 | 7.5 High |
| Possible memory leak or kernel exceptions caused by reading kernel heap data after free or NULL pointer dereference kernel exception. | ||||
| CVE-2025-46711 | 1 Imaginationtech | 2 Ddk, Graphics Ddk | 2025-10-17 | 5.5 Medium |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer dereference kernel exceptions. | ||||
| CVE-2025-25177 | 1 Imaginationtech | 1 Graphics Ddk | 2025-09-23 | 5.1 Medium |
| Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions. | ||||
| CVE-2025-8109 | 1 Imaginationtech | 1 Graphics Ddk | 2025-09-08 | 8.8 High |
| Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory. | ||||
| CVE-2025-6573 | 1 Imaginationtech | 1 Graphics Ddk | 2025-08-12 | 9.8 Critical |
| Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from the trusted execution environment (TEE). | ||||
| CVE-2025-0467 | 1 Imaginationtech | 2 Ddk, Graphics Ddk | 2025-07-11 | 8.2 High |
| Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory. | ||||
| CVE-2024-43701 | 1 Imaginationtech | 1 Graphics Ddk | 2024-10-15 | 7.8 High |
| Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU. | ||||
Page 1 of 1.