CVE-2025-25176Resource Exposure in DDK

Severity
9.1CRITICALNVD
EPSS
0.0%
top 85.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

🔴Vulnerability Details

1
GHSA
GHSA-g4x2-4cxv-hpg5: Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of2026-01-13

📋Vendor Advisories

1
Microsoft
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.2025-07-08