CVE-2025-58408
GPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling code
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.9EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
01 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free.
The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
Imagination Technologies · Graphics DDKWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →