CVE-2025-25180
GPU DDK - Insufficient validation in RGXCREATEFREELIST creates corrupt freelist
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 0.1%KEV nãoPoC —Patch —
Lifecycle
Jul 14, 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Software installed and run as a non-privileged user may conduct improper GPU system calls to subvert GPU HW to write to arbitrary physical memory pages.
Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel and drivers running on the platform altering their behaviour.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Imagination Technologies · Graphics DDKWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →