CVE-2025-25176 — Resource Exposure in DDK
Severity
9.1CRITICALNVD
EPSS
0.0%
top 85.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Description
Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2
Affected Packages7 packages
🔴Vulnerability Details
1GHSA▶
GHSA-g4x2-4cxv-hpg5: Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of↗2026-01-13
📋Vendor Advisories
1Microsoft▶
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.↗2025-07-08