---
id: CVE-2025-58407
title: >-
  Kernel or driver software installed on a Guest VM may post improper commands
  to the GPU Firmware to exploit a TOCTOU race condition and trigger a read
  and/or write of data outside the allotted memory escaping the virtual machine.
summary: >-
  Kernel or driver software installed on a Guest VM may post improper commands
  to the GPU Firmware to exploit a TOCTOU race condition and trigger a read
  and/or write of data outside the allotted memory escaping the virtual machine.
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-367
vendor: imaginationtech
product: ddk
affected:
  - ddk = 25.2
published: '2025-11-17'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58407'
references:
  - url: 'https://www.imaginationtech.com/gpu-driver-vulnerabilities/'
    label: 367425dc-4d06-4041-9650-c2dc6aaa27ce
tags:
  - nvd
epss: 0.00193
epssPercentile: 0.08245
ingestedAt: '2026-10-07T21:54:15.064Z'
---

## Overview

Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine.

## Affected

- `ddk = 25.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
