Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Nov 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Nov 2025 17:30:00 +0000

Type Values Removed Values Added
Description Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.
Title GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSet
Weaknesses CWE-367
References

cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published:

Updated: 2025-11-17T17:35:06.099Z

Reserved: 2025-09-01T08:00:07.348Z

Link: CVE-2025-58407

cve-icon Vulnrichment

Updated: 2025-11-17T17:35:02.390Z

cve-icon NVD

Status : Received

Published: 2025-11-17T18:15:57.880

Modified: 2025-11-17T18:15:57.880

Link: CVE-2025-58407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.