CVE-2025-58408 Details
Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free. The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use.
A use-after-free vulnerability has been identified in the GPU driver developed by Imagination Technologies. This issue affects software running as a non-privileged user within a Guest virtual machine, specifically in DDK Releases up to and including 24.3 RTM. The vulnerability arises from improper GPU system calls that trigger reads of stale data, including handles to resources with unbalanced reference counts. This mismanagement can lead to kernel exceptions and unauthorized writes, creating a use-after-free condition.
The DDK kernel module has been updated to address this vulnerability by correcting the improper management of GPU system calls, preventing access to stale data that could lead to use-after-free conditions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| imaginationtech ddk | <= 25.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 29, 2025 | Initial Analysis | [email protected] |
| Dec 1, 2025 | CVE Modified | CISA-ADP |
| Dec 1, 2025 | New CVE Received | imaginationtech |