CVE 5.9 MEDIUM

GPU DDK – KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling code_CVE-2025-58408

5.9 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Description

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free.

The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use.

Basic Information

ID CVE-2025-58408
Source imaginationtech
Published Dec 1, 2025 at 11:16
Modified Dec 1, 2025 at 18:06

Affected Product

Vendor Imagination Technologies
Product Graphics DDK
Version 1.15 RTM
Affected Versions Imagination Technologies Graphics DDK 1.15 RTM
Imagination Technologies Graphics DDK 1.17 RTM
Imagination Technologies Graphics DDK 1.18 RTM
Imagination Technologies Graphics DDK 23.2 RTM

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.