CVE-2025-46711: GPU DDK - NULL Pointer dereference occurs in LockHandle on bridge entry when connection misused
Published Sep 22, 2025
·Updated
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer dereference kernel exceptions.
Affected Software
2 affected components
Imaginationtech Ddk>=1.17<=25.1
Google Android
Event History
Sep 22, 2025
CVE Published
via MITRE·10:21 AM
Data Sourced
via MITRE·10:21 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Dec 1, 2025
Data Sourced
via Android·12:00 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-46711?
CVE-2025-46711 is classified as a high severity vulnerability due to the potential for denial of service through kernel exceptions.
2
How do I fix CVE-2025-46711?
To remediate CVE-2025-46711, update the Imagination Technologies DDK to a version higher than 25.1.
3
What type of attacks can CVE-2025-46711 enable?
CVE-2025-46711 can enable denial of service attacks by causing NULL pointer dereferences in the kernel.
4
Which software versions are vulnerable to CVE-2025-46711?
Versions of Imagination Technologies DDK between 1.17 and 25.1 are vulnerable to CVE-2025-46711.
5
Who is affected by CVE-2025-46711?
Users running applications with the Imagination Technologies DDK as a non-privileged user may be affected by CVE-2025-46711.