CVE-2025-58408

CVE-2025-58408: GPU DDK - KASAN Read UAF in the PVRSRVBridgeRGXSubmitTransfer2 due to improper error handling code

Vendor Imagination Technologies
Product Graphics DDK
Weakness CWE-416
Published December 1, 2025
Last update December 1, 2025

CVSS base score

What the vulnerability does

01Description

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger reads of stale data that can lead to kernel exceptions and write use-after-free. The Use After Free common weakness enumeration was chosen as the stale data can include handles to resources in which the reference counts can become unbalanced. This can lead to the premature destruction of a resource while in use.

Key dates

02Disclosure timeline

December 1, 2025 CVE published
December 1, 2025 Record updated