Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 09 Jan 2026 02:15:00 +0900

Type Values Removed Values Added
First Time appeared Imaginationtech ddk
CPEs cpe:2.3:a:imaginationtech:ddk:25.2:rtm:*:*:*:*:*:*
Vendors & Products Imaginationtech ddk

Tue, 18 Nov 2025 18:15:00 +0900

Type Values Removed Values Added
First Time appeared Imaginationtech
Imaginationtech graphics Ddk
Vendors & Products Imaginationtech
Imaginationtech graphics Ddk

Tue, 18 Nov 2025 03:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 02:30:00 +0900

Type Values Removed Values Added
Description Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.
Title GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSet
Weaknesses CWE-367
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: imaginationtech

Published:

Updated: 2025-11-17T17:35:06.099Z

Reserved: 2025-09-01T08:00:07.348Z

Link: CVE-2025-58407

cve-icon Vulnrichment

Updated: 2025-11-17T17:35:02.390Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-17T18:15:57.880

Modified: 2026-01-08T17:13:38.533

Link: CVE-2025-58407

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-18T18:06:15Z

Weaknesses