Improper GPU System Calls Leading to Memory Manipulation in Imagination Technologies Products
CVE-2025-0478

7.8HIGH

Key Information:

Vendor
CVE Published:
24 March 2025

What is CVE-2025-0478?

A vulnerability exists in Imagination Technologies GPU drivers where software operating with non-privileged user rights may improperly invoke GPU system calls. This flaw can lead to unintended reads and writes to arbitrary physical memory pages, potentially corrupting data not allocated by the GPU driver. The exploit may affect memory pages currently utilized by the kernel and other drivers, causing unpredictable changes in functionality and system behavior.

Affected Version(s)

Graphics DDK Linux 1.15 RTM <= 24.3 RTM2

Graphics DDK Linux 25.1 RTM

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.