CVE-2025-58411Use After Free in DDK

CWE-416Use After Free2 documents2 sources
Severity
8.8HIGHNVD
EPSS
0.0%
top 99.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creating a potential use after free scenario. Improper resource management and reference counting on an internal resource caused scenario where potential write use after free was present.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages2 packages

CVEListV5imagination_technologies/graphics_ddk23.2 RTM25.2 RTM+3

🔴Vulnerability Details

1
GHSA
GHSA-v295-9qvv-gpgw: Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources reference counting creat2026-01-13