{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-13T19:44:48.806","vulnerabilities":[{"cve":{"id":"CVE-2025-58409","sourceIdentifier":"367425dc-4d06-4041-9650-c2dc6aaa27ce","published":"2026-01-13T17:15:57.680","lastModified":"2026-06-17T09:44:25.070","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.\n\nUnder certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.\n\nThis attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory."},{"lang":"es","value":"El software instalado y ejecutado como un usuario no privilegiado puede realizar llamadas al sistema de GPU impropias para subvertir el hardware de la GPU y escribir en páginas de memoria física arbitrarias.\n\nBajo ciertas circunstancias, este exploit podría usarse para corromper páginas de datos no asignadas por el controlador de la GPU, sino páginas de memoria en uso por el kernel y los controladores que se ejecutan en la plataforma, alterando su comportamiento.\n\nEste ataque puede llevar a la GPU a realizar operaciones de escritura en búferes internos restringidos de la GPU que pueden conducir a un efecto de segundo orden de memoria física arbitraria corrompida."}],"affected":[{"source":"367425dc-4d06-4041-9650-c2dc6aaa27ce","affectedData":[{"vendor":"Imagination Technologies","product":"Graphics DDK","defaultStatus":"unknown","platforms":["Linux","Android"],"versions":[{"version":"1.15 RTM","versionType":"custom","status":"affected"},{"version":"1.17 RTM","versionType":"custom","status":"affected"},{"version":"1.18 RTM","versionType":"custom","status":"affected"},{"version":"23.2 RTM","lessThanOrEqual":"25.2 RTM","versionType":"custom","status":"affected"},{"version":"25.3 RTM","versionType":"custom","status":"unaffected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":3.5,"baseSeverity":"LOW","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-14T15:03:50.761732Z","id":"CVE-2025-58409","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"367425dc-4d06-4041-9650-c2dc6aaa27ce","type":"Secondary","description":[{"lang":"en","value":"CWE-119"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*","versionEndExcluding":"25.3","matchCriteriaId":"99A33CBA-49C5-4976-B668-88F87F0FF575"}]}]}],"references":[{"url":"https://www.imaginationtech.com/gpu-driver-vulnerabilities/","source":"367425dc-4d06-4041-9650-c2dc6aaa27ce","tags":["Vendor Advisory"]}]}}]}