CVE-2025-10865
7.8Imagination Technologies · Graphics DDK
A use after free vulnerability in Imagination Technologies Graphics DDK allows a local, authenticated user to trigger GPU memory mismanagement via improper system calls.
Executive summary
A use after free vulnerability in Imagination Technologies Graphics DDK creates a risk of local privilege escalation or system instability.
Vulnerability
This is a use after free vulnerability (CWE-416) resulting from improper reference counting during GPU system calls, which can be triggered by an authenticated, non-privileged local user.
Business impact
Successful exploitation allows a local user to achieve high impact across confidentiality, integrity, and availability. Given the CVSS score of 7.8, this vulnerability poses a significant risk to workstations or servers utilizing affected graphics drivers, potentially leading to unauthorized data access or complete system compromise.
Remediation
Immediate Action: Update the Imagination Technologies Graphics DDK to version 25.3 RTM or later to resolve the reference counting flaw.
Proactive Monitoring: Monitor system logs for unusual GPU driver crashes or kernel-level errors that may indicate exploitation attempts.
Compensating Controls: Restrict access to the affected system to trusted users only, as the vulnerability requires local access to execute the malicious GPU system calls.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this issue necessitates prompt action, particularly in multi-user environments where local privilege escalation is a primary concern. Administrators should prioritize updating the Graphics DDK to the version specified by the vendor to eliminate the underlying memory mismanagement flaw.