Memory Access Vulnerability in Guest VM Affecting Imagination Technologies GPU Drivers
CVE-2024-47893

6.5MEDIUM

Key Information:

Vendor
CVE Published:
17 May 2025

What is CVE-2024-47893?

A vulnerability has been identified in the GPU drivers provided by Imagination Technologies, where kernel software operating within a Guest Virtual Machine (VM) can exploit vulnerabilities in shared memory with the GPU firmware. This exploitation enables unauthorized reading and writing of data outside the intended GPU memory space, posing risks to the security and integrity of virtualized environments. Addressing this vulnerability is crucial for maintaining robust security in systems utilizing guest virtual machines.

Affected Version(s)

Graphics DDK Linux 1.15 RTM <= 24.3 RTM

Graphics DDK Linux 25.1 RTM

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.