Out-of-bounds write in PowerVR GPU DDK - CVE-2024-52935

 

Out-of-bounds write in PowerVR GPU DDK - CVE-2024-52935

Published: February 3, 2025


Vulnerability identifier: #VU103558
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52935
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a guest OS to execute arbitrary code.

The vulnerability exists due to a boundary error when processing untrusted input. Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest’s virtualised GPU memory.


Affected software

PowerVR GPU DDK
Samsung Mobile Firmware
Google Android

How to mitigate CVE-2024-52935

Install updates from vendor's website.

Samsung Mobile Firmware - update to SMR-MAR-2025
Google Android - addressed in versions 12L 2025-02-05, 12 2025-02-05, 13 2025-02-05, 14 2025-02-05, 15 2025-02-05

External References

Related Security Bulletins