---
id: CVE-2025-58410
title: >-
  Software installed and run as a non-privileged user may conduct improper GPU
  system calls to gain write permissions to memory buffers exported as
  read-only.


  This is caused by improper handling of the memory protections for the buffer
  re…
summary: >-
  Software installed and run as a non-privileged user may conduct improper GPU
  system calls to gain write permissions to memory buffers exported as
  read-only.


  This is caused by improper handling of the memory protections for the buffer
  re…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-280
vendor: imaginationtech
product: ddk
affected:
  - ddk = 23.3
  - ddk = 24.1
  - ddk = 24.2
  - ddk = 24.3
  - ddk = 25.1
  - ddk = 25.2
published: '2025-11-17'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58410'
references:
  - url: 'https://www.imaginationtech.com/gpu-driver-vulnerabilities/'
    label: 367425dc-4d06-4041-9650-c2dc6aaa27ce
tags:
  - nvd
epss: 0.00276
epssPercentile: 0.18326
ingestedAt: '2026-10-07T21:54:15.061Z'
---

## Overview

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only.

This is caused by improper handling of the memory protections for the buffer resource.

## Affected

- `ddk = 23.3`
- `ddk = 24.1`
- `ddk = 24.2`
- `ddk = 24.3`
- `ddk = 25.1`
- `ddk = 25.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
