Vulnerability Description
Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imaginationtech | Ddk | 25.2 |
Related Weaknesses (CWE)
References
- https://www.imaginationtech.com/gpu-driver-vulnerabilities/Vendor Advisory
FAQ
What is CVE-2025-58407?
CVE-2025-58407 is a vulnerability with a CVSS score of 7.4 (HIGH). Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory ...
How severe is CVE-2025-58407?
CVE-2025-58407 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-58407?
Check the references section above for vendor advisories and patch information. Affected products include: Imaginationtech Ddk.