Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.imaginationtech.com/gpu-driver-vulnerabilities/ |
![]() ![]() |
History
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 14 Jul 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
Mon, 14 Jul 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. | |
Title | GPU DDK - Insufficient validation in RGXCREATEFREELIST creates corrupt freelist | |
Weaknesses | CWE-823 | |
References |
|

Status: PUBLISHED
Assigner: imaginationtech
Published: 2025-07-14T01:36:14.742Z
Updated: 2025-07-14T14:57:16.398Z
Reserved: 2025-02-03T18:12:50.622Z
Link: CVE-2025-25180

Updated: 2025-07-14T14:56:42.744Z

Status : Awaiting Analysis
Published: 2025-07-14T02:15:21.983
Modified: 2025-07-15T13:14:24.053
Link: CVE-2025-25180

No data.