GPU Firmware Exploit in Guest VM for Imagination Technologies
CVE-2025-0467

8.2HIGH

Key Information:

Vendor
CVE Published:
18 April 2025

What is CVE-2025-0467?

A vulnerability exists in the GPU firmware that allows kernel software running inside a Guest Virtual Machine (VM) to exploit shared memory with the GPU. This can lead to unauthorized memory writes outside of the VM's isolated GPU memory space, posing a security risk to the integrity of the host system and other VMs. Proper mitigation strategies are essential to prevent potential exploits from compromising sensitive data and system performance.

Affected Version(s)

Graphics DDK Linux 1.15 RTM <= 24.3 RTM

Graphics DDK Linux 25.1 RTM

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.