CVE-2025-58408 – GPU DDK – KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling code

The following table lists the changes that have been made to the
CVE-2025-58408 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 367425dc-4d06-4041-9650-c2dc6aaa27ce

    Dec. 01, 2025

    Action Type Old Value New Value
    Added Description Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free.

    The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use.

    Added CWE CWE-416
    Added Reference https://www.imaginationtech.com/gpu-driver-vulnerabilities/
Share the Post:

Related Posts