CVE-2024-52937 Details
Description
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.
A vulnerability exists in the GPU driver provided by Imagination Technologies, specifically in the Graphics Processing Unit (GPU) Driver Development Kit (DDK) version 24.2 RTM2 and prior. This vulnerability allows kernel software running inside a Guest Virtual Machine (VM) to exploit memory shared with the GPU firmware. The exploitation can lead to writing data outside the Guest's virtualized GPU memory, potentially causing unauthorized access to physical memory or corruption of memory used by the kernel and other drivers.
Users can update to the DDK version 24.3 or later, where this vulnerability has been addressed by introducing protections that prevent the out-of-bounds writes from occurring.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 13, 2025CISA-ADP
Assessed Jan 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-823 | Use of Out-of-range Pointer Offset | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| Imagination Technologies GPU DDK | <= 24.2 RTM2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 13, 2025 | CVE Modified | CISA-ADP |
| Jan 13, 2025 | New CVE Received | imaginationtech |
Volerion