CVE-2024-47896 Details
Description
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
A vulnerability exists in the GPU driver provided by Imagination Technologies, specifically in the Graphics Processing Unit (GPU) Driver Development Kit (DDK) version 24.3 and earlier. This vulnerability allows kernel software running inside a Guest Virtual Machine (VM) to exploit memory shared with the GPU firmware, causing unauthorized writes to physical memory outside the Guest's allocated GPU memory. This issue arises from improper handling of commands sent to the GPU firmware, which can be manipulated to overwrite memory arbitrarily.
Users can update to the latest version of the Imagination Technologies GPU Driver Development Kit, which includes patches for this vulnerability. Instructions for updating the driver can be found on the Imagination Technologies website or through their support channels.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 22, 2025CISA-ADP
Assessed Mar 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-823 | Use of Out-of-range Pointer Offset | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| Imagination Technologies GPU DDK | <= 24.2 RTM2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 5, 2025 | CVE Modified | CISA-ADP |
| Feb 22, 2025 | New CVE Received | imaginationtech |
Volerion