CVE-2025-25176: GPU DDK - GPU Register value contents leaked from secure workloads to non-secure world
Published Jan 13, 2026
·Updated
Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in the non-secure environment of a platform.
Affected Software
1 affected component
Imaginationtech Ddk<25.3
Event History
Jan 13, 2026
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25176?
CVE-2025-25176 is classified as a high severity vulnerability due to the potential for sensitive GPU register values to be leaked.
2
How do I fix CVE-2025-25176?
To mitigate CVE-2025-25176, update the Imagination Tech DDK software to version 25.3 or later.
3
What are the potential impacts of CVE-2025-25176?
The potential impacts of CVE-2025-25176 include unauthorized access to sensitive data from secure workloads, which can compromise system integrity.
4
Which software versions are affected by CVE-2025-25176?
CVE-2025-25176 affects all versions of the Imagination Tech DDK prior to 25.3.
5
In which environments does CVE-2025-25176 occur?
CVE-2025-25176 occurs in environments where applications operate in a non-secure world while accessing secure workload data.