Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.imaginationtech.com/gpu-driver-vulnerabilities/ | 
                     | 
            
History
                    Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Mon, 14 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        cvssV3_1
         
 
  | 
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        epss
         
  | 
Mon, 14 Jul 2025 02:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. | |
| Title | GPU DDK - Insufficient validation in RGXCREATEFREELIST creates corrupt freelist | |
| Weaknesses | CWE-823 | |
| References | 
         | 
Status: PUBLISHED
Assigner: imaginationtech
Published: 2025-07-14T01:36:14.742Z
Updated: 2025-07-14T14:57:16.398Z
Reserved: 2025-02-03T18:12:50.622Z
Link: CVE-2025-25180
Updated: 2025-07-14T14:56:42.744Z
Status : Awaiting Analysis
Published: 2025-07-14T02:15:21.983
Modified: 2025-07-15T13:14:24.053
Link: CVE-2025-25180
No data.