CRITICAL🇵🇱 Wersja polska

CVE-2025-25176

CVSS 9.1v3.1pub. 2026-01-13upd. 2026-01-30

Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.

🤖 AI Analysis
How it works

The vulnerability results from improper resource isolation (CWE-668) between the secure and unsecured execution environments of the platform. Intermediate register values belonging to secure workloads can be read by tasks dispatched from applications running in the unsecured environment. An attacker can schedule a properly crafted workload from the unsecured environment level and thereby intercept sensitive data from the isolated secure context registers.

Impact

An attacker can gain unauthorized access to sensitive data processed by secure workloads (confidentiality breach) and potentially modify this data (integrity breach), threatening the trusted execution environment isolation mechanisms on the platform.

Mitigation & patch

Apply patches available from the manufacturer according to the references: https://www.imaginationtech.com/gpu-driver-vulnerabilities/

Who is affected

Imagination Technologies DDK — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Imaginationtech Ddk

    APP
    Imaginationtech
    < 25.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-16280CRITICAL9.8PL ✓same product

Integer overflow w sterowniku GPU Imagination — błędne mapowanie pamięci fizycznej

CVE-2026-21732CRITICAL9.6PL ✓same product

Out-of-bounds write w kompilatorze GPU shader Imagination Technologies DDK

CVE-2025-13952CRITICAL9.8PL ✓same product

Use-after-free w kompilatorze shaderów GPU biblioteki Imagination DDK

CVE-2026-49743HIGH7.8PL ✓same product

Use-After-Free w sterowniku GPU — eskalacja uprawnień przez manipulację synchronizacją

CVE-2026-49744HIGH7.8PL ✓same product

Privilege escalation w GPU Firmware — zapis poza wirtualną pamięcią GPU gościa