CVE-2025-46708 Details
Description
Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.
A vulnerability exists in the GPU driver of Imagination Technologies that allows software running in a Guest VM to improperly manage GPU system calls. This mismanagement can block other Guest VMs from utilizing the GPU for their workloads. The issue affects DDK Releases up to and including 24.1 RTM.
Users can update to the latest DDK release, which includes a patch for this vulnerability by preventing the resource blocking from occurring.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-280 | Improper Handling of Insufficient Permissions or Privileges | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| imaginationtech ddk | >= 23.2, < 24.2 1.15 rtm 1.17 rtm 1.18 rtm |
CPE
Remediation
| |
| google android | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | Initial Analysis | [email protected] |
| Jul 1, 2025 | CVE Modified | CISA-ADP |
| Jun 27, 2025 | New CVE Received | imaginationtech |