CVE-2025-46708Improper Handling of Insufficient Permissions or Privileges in DDK

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 91.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateSep 1

Description

Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU.

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 0.9 | Impact: 3.4

Affected Packages3 packages

NVDimaginationtech/ddk23.224.2+3
CVEListV5imagination_technologies/graphics_ddk23.2 RTM24.1 RTM+3

🔴Vulnerability Details

1
GHSA
GHSA-jvrp-c78h-qqvj: Software installed and running inside a Guest VM may conduct improper GPU system calls to prevent other Guests from running work on the GPU2025-06-27

📋Vendor Advisories

1
Android
CVE-2025-46708: PowerVR-GPU2025-09-01