Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.
The vulnerability results from improper resource isolation (CWE-668) between the secure and unsecured execution environments of the platform. Intermediate register values belonging to secure workloads can be read by tasks dispatched from applications running in the unsecured environment. An attacker can schedule a properly crafted workload from the unsecured environment level and thereby intercept sensitive data from the isolated secure context registers.
An attacker can gain unauthorized access to sensitive data processed by secure workloads (confidentiality breach) and potentially modify this data (integrity breach), threatening the trusted execution environment isolation mechanisms on the platform.
Apply patches available from the manufacturer according to the references: https://www.imaginationtech.com/gpu-driver-vulnerabilities/
Imagination Technologies DDK — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NImaginationtech Ddk
APPImaginationtech< 25.3
Related vulnerabilities
Integer overflow w sterowniku GPU Imagination — błędne mapowanie pamięci fizycznej
Out-of-bounds write w kompilatorze GPU shader Imagination Technologies DDK
Use-after-free w kompilatorze shaderów GPU biblioteki Imagination DDK
Use-After-Free w sterowniku GPU — eskalacja uprawnień przez manipulację synchronizacją
Privilege escalation w GPU Firmware — zapis poza wirtualną pamięcią GPU gościa