CVE-2025-58409
CVE-2025-58409 is a low-severity vulnerability in Imaginationtech Ddk with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-119.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- EPSS exploit prediction: 0% (3rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-2233
- Weakness: CWE-119
- Affected product: Imaginationtech Ddk
- Published:
- Last modified:
Description
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory.
Frequently asked questions
- What is CVE-2025-58409?
- Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour. This attack can lead the GPU to perform write operations on restricted internal GPU buffers that can lead to a second order affect of corrupted arbitrary physical memory.
- How severe is CVE-2025-58409?
- CVE-2025-58409 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over physical access with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability none.
- Is CVE-2025-58409 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (3rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-58409?
- CVE-2025-58409 affects Imaginationtech Ddk. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-58409?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-58409 have an EU (EUVD) identifier?
- Yes. CVE-2025-58409 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-2233.
- When was CVE-2025-58409 published?
- CVE-2025-58409 was published on 2026-01-13 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:imaginationtech:ddk:*:*:*:*:*:*:*:*
More vulnerabilities in Imaginationtech Ddk
- CVE-2026-16280 — Critical (CVSS 9.8): An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address…
- CVE-2025-13952 — Critical (CVSS 9.8): A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a…
- CVE-2026-21732 — Critical (CVSS 9.6): A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write…
- CVE-2025-25176 — Critical (CVSS 9.1): Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in…
- CVE-2025-58411 — High (CVSS 8.8): Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of…
- CVE-2025-0467 — High (CVSS 8.2): Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data…
All CVEs affecting Imaginationtech Ddk →
Other CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) vulnerabilities
- CVE-2026-77946 — Critical (CVSS 10.0): A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function…
- CVE-2026-76008 — Critical (CVSS 10.0): A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file…
- CVE-2026-75784 — Critical (CVSS 10.0): A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of…
- CVE-2026-74843 — Critical (CVSS 10.0): A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function…
- CVE-2026-16367 — Critical (CVSS 10.0): Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox…
- CVE-2026-2778 — Critical (CVSS 10.0): Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component. This vulnerability was fixed in…