Executive brief
A vulnerability was identified in the Linux kernel's AMD GPU driver affecting systems with Video Core Next (VCN) hardware. The VCN encoder and decoder components were incorrectly attempting to process 64-bit user fence writes, which the hardware does not support. This could lead to system instability or unexpected behavior when processing video encoding tasks.
Technical details
A vulnerability in the AMDGPU driver's VCN (Video Core Next) v5.0.1 implementation allowed for Command Submission (CS) with user fences on hardware that does not support 64-bit user fence writes. The root cause was the lack of the 'no_user_fence' flag in the ring functions for VCN encoder and decoder rings. An attacker with local access to the GPU interface could potentially trigger undefined behavior or kernel crashes by submitting unsupported fence operations. The fix involves setting the 'no_user_fence' parameter to true, ensuring the driver rejects these unsupported submissions. Patches have been applied to various stable branches of the Linux kernel.
Affected products
- Linux Linux 6.14, 6.18.33, 7.0.10
Timeline
- 2026-07-19: disclosed: Initial publication of the CVE record.
- 2026-07-19: advisory