Out-of-bounds write in PowerVR GPU DDK - CVE-2024-52935
Published: February 3, 2025
Vulnerability identifier: #VU103558
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52935
CWE-ID: CWE-787
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a guest OS to execute arbitrary code.
The vulnerability exists due to a boundary error when processing untrusted input. Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest’s virtualised GPU memory.
Affected software
PowerVR GPU DDK
Samsung Mobile Firmware
Google Android
Samsung Mobile Firmware
Google Android
How to mitigate CVE-2024-52935
Install updates from vendor's website.
Samsung Mobile Firmware - update to SMR-MAR-2025
Google Android - addressed in versions 12L 2025-02-05, 12 2025-02-05, 13 2025-02-05, 14 2025-02-05, 15 2025-02-05
Google Android - addressed in versions 12L 2025-02-05, 12 2025-02-05, 13 2025-02-05, 14 2025-02-05, 15 2025-02-05