CVE-2025-58407: GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSet
Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58407?
CVE-2025-58407 is considered a critical vulnerability due to its potential for allowing unauthorized access to memory beyond the allocated bounds.
How do I fix CVE-2025-58407?
To mitigate CVE-2025-58407, users should update their GPU firmware and related driver software to the latest patched versions provided by the vendor.
What systems are affected by CVE-2025-58407?
CVE-2025-58407 specifically affects systems running the Imaginationtech DDK version 25.2-rtm.
What is the impact of exploit CVE-2025-58407?
Exploitation of CVE-2025-58407 could lead to unauthorized data access or corruption by allowing reads and writes outside of the designated virtual memory bounds.
Is CVE-2025-58407 a local or remote vulnerability?
CVE-2025-58407 is primarily a local vulnerability that requires an attacker to have access to the Guest VM to exploit it.