Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ |
|
History
Tue, 08 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 04 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. | |
| Title | GPU DDK - ui64RobustnessAddress can overwrite Freelist / HWRT (and bypass PMMETA) | |
| Weaknesses | CWE-280 | |
| References |
|
Status: PUBLISHED
Assigner: imaginationtech
Published: 2025-04-04T15:39:37.798Z
Updated: 2025-04-07T14:48:05.895Z
Reserved: 2025-01-14T09:32:36.718Z
Link: CVE-2025-0468
Updated: 2025-04-07T14:48:00.663Z
Status : Awaiting Analysis
Published: 2025-04-04T16:15:17.873
Modified: 2025-04-07T15:15:42.223
Link: CVE-2025-0468
No data.