CVE-2025-58411 — Use After Free in DDK
Severity
8.8HIGHNVD
EPSS
0.0%
top 99.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 13
Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario.
Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0
Affected Packages2 packages
🔴Vulnerability Details
1GHSA▶
GHSA-v295-9qvv-gpgw: Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creat↗2026-01-13