Back to search
CVE-2025-58407
Published: Nov 17, 2025
Modified: Nov 17, 2025
PUBLISHED
Description
Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.
| Vendor | Product | Versions |
|---|---|---|
Imagination Technologies | Graphics DDK | unaffected 25.1 RTM2affected 25.2 RTM1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now