Junglewise Threat Intelligence

CVE-2026-63845: Linux kernel amdgpu unsupported user fence in JPEG v4.0 ring

CVE-2026-63845 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's AMD GPU driver could allow local users to trigger system instability or crashes when using JPEG hardware acceleration. The issue stems from the driver incorrectly attempting to use a synchronization feature (user fences) that the JPEG v4.0 hardware does not support. This could lead to failed operations or kernel errors during media processing tasks.

Technical details

In the Linux kernel's amdgpu driver, the JPEG v4.0 hardware engine does not support 64-bit user fence writes. Prior to this fix, the driver did not explicitly reject Command Submission (CS) requests that included user fences for this specific hardware ring. This mismatch between software expectations and hardware capabilities can lead to undefined behavior or kernel panics. The fix involves setting the 'no_user_fence' flag to true for the JPEG v4.0 ring, ensuring that the kernel correctly rejects these unsupported submissions. This is a local vulnerability requiring the ability to submit commands to the GPU.

Affected products

  • Linux Linux 5.19 to 7.0.10

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References