CVE-2025-0467

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*

History

11 Jul 2025, 16:27

Type Values Removed Values Added
References () https://www.imaginationtech.com/gpu-driver-vulnerabilities/ - () https://www.imaginationtech.com/gpu-driver-vulnerabilities/ - Vendor Advisory
CPE cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*
First Time Imaginationtech
Imaginationtech ddk
Summary
  • (es) El software del kernel instalado y ejecutándose dentro de una máquina virtual invitada puede explotar la memoria compartida con el firmware de la GPU para escribir datos fuera de la memoria de la GPU virtualizada de la máquina virtual invitada.

21 Apr 2025, 14:23

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2

18 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-18 01:15

Updated : 2025-07-11 16:27


NVD link : CVE-2025-0467

Mitre link : CVE-2025-0467

CVE.ORG link : CVE-2025-0467


JSON object : View

Products Affected

imaginationtech

  • ddk
CWE
CWE-823

Use of Out-of-range Pointer Offset