5.2

CVE-2025-46707

GPU DDK - Guest VM can override its own FW VZ connection state after the FW has close it

Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imaginationtech ≫ Ddk Version >= 23.2 < 24.1
   Google ≫ Android Version -
   Linux ≫ Linux Kernel Version -
Imaginationtech ≫ Ddk Version 1.15 Update rtm
   Google ≫ Android Version -
   Linux ≫ Linux Kernel Version -
Imaginationtech ≫ Ddk Version 1.17 Update rtm
   Google ≫ Android Version -
   Linux ≫ Linux Kernel Version -
Imaginationtech ≫ Ddk Version 1.18 Update rtm
   Google ≫ Android Version -
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.027
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 5.2 2 2.7
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://www.imaginationtech.com/gpu-driver-vulnerabilities/
Vendor Advisory