TOCTOU Race Condition in GPU Firmware on Guest VM by Imagination Technologies
Posted: Tue Nov 18, 2025 4:47 am
A security issue exists in the GPU firmware provided by Imagination Technologies, where a TOCTOU (Time of Check to Time of Use) race condition can occur. This vulnerability may allow a crafted guest virtual machine (VM) to send improper commands to the GPU firmware. As a result, it can lead to unauthorized read and/or write operations that access data beyond the designated memory bounds of the virtual machine, potentially compromising the integrity and confidentiality of the memory space.
https://securityvulnerability.io/vulner ... 2025-58407
https://securityvulnerability.io/vulner ... 2025-58407