CVE-2025-8109 Details
Description
Software installed and run as a non-privileged user may conduct ptrace system calls to issue writes to GPU origin read only memory.
A vulnerability exists in Imagination Technologies GPU drivers, specifically in the GPU DDK, all versions up to and including 24.3. This vulnerability allows software running as a non-privileged user to use ptrace system calls to write data to GPU memory that is normally read-only. The issue arises from improper validation in the GPU driver, which can be exploited to disrupt GPU operations and potentially cause system instability.
Users can update to the latest version of the Imagination Technologies GPU DDK, which includes patches to prevent ptrace from writing to read-only memory areas. Instructions for updating the GPU DDK can be found on the Imagination Technologies website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 4, 2025CISA-ADP
Assessed Aug 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | imaginationtech | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-280 | Improper Handling of Insufficient Permissions or Privileges | imaginationtech |
Affected Products
| Product | Versions |
|---|---|
| Imagination Technologies GPU DDK | <= 24.2 RTM2 <= 24.3 RTM |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | imaginationtech |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2025 | CVE Modified | CISA-ADP |
| Aug 5, 2025 | CVE Modified | CISA-ADP |
| Aug 4, 2025 | New CVE Received | imaginationtech |
Volerion