CVE-2025-25179: GPU DDK - Freelist GPU VA can be remapped to another reservation/PMR to trigger GPU arbitrary write to physical memory
Published Jun 2, 2025
·Updated
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
Affected Software
2 affected components
Imaginationtech Ddk<=24.3
Google Android
Event History
Jun 2, 2025
CVE Published
via MITRE·04:19 AM
Data Sourced
via MITRE·04:19 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Sep 2, 2025
Data Sourced
via Android·12:00 AM
SeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25179?
CVE-2025-25179 is considered a high severity vulnerability due to its potential to allow unauthorized memory access.
2
How do I fix CVE-2025-25179?
To fix CVE-2025-25179, update the Imagination Technology DDK to a version higher than 24.3.
3
What kind of systems are affected by CVE-2025-25179?
CVE-2025-25179 affects systems running the Imagination Technology DDK version 24.3 or lower.
4
What can attackers achieve with CVE-2025-25179?
Attackers could exploit CVE-2025-25179 to manipulate GPU hardware for unauthorized memory access.
5
Who is responsible for addressing CVE-2025-25179?
The vendor, Imagination Technologies, is responsible for providing a patch or update to address CVE-2025-25179.