CVE-2025-10865Use After Free in DDK

CWE-416Use After Free2 documents2 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 94.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a potential use after free. Improper reference counting on an internal resource caused scenario where potential for use after free was present.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5imagination_technologies/graphics_ddk23.2 RTM25.2 RTM+3

🔴Vulnerability Details

1
GHSA
GHSA-99w5-vv22-2rrf: Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reference counting to cause a pote2026-01-13