Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-11810 Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech ddk
CPEs cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*
Vendors & Products Imaginationtech
Imaginationtech ddk

Mon, 21 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Apr 2025 00:45:00 +0000

Type Values Removed Values Added
Description Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
Title GPU DDK - rgxfw_hwperf_get_packet_buffer OOB write
Weaknesses CWE-823
References

cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published:

Updated: 2025-04-21T13:34:48.602Z

Reserved: 2025-01-14T09:32:35.173Z

Link: CVE-2025-0467

cve-icon Vulnrichment

Updated: 2025-04-21T13:34:38.629Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-18T01:15:32.130

Modified: 2025-07-11T16:27:38.847

Link: CVE-2025-0467

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-17T12:08:35Z