Executive brief
A vulnerability was identified in the Linux kernel's AMD GPU driver affecting systems with VCN 4.0.5 hardware. The video encoding and decoding components were incorrectly allowing certain memory synchronization requests (user fences) that the hardware does not support. This could lead to unpredictable system behavior or stability issues when processing video data.
Technical details
A vulnerability in the Linux kernel's DRM amdgpu driver (specifically in vcn_v4_0_5.c) stems from the VCN encoder and decoder rings not supporting 64-bit user fence writes. Prior to the fix, the driver did not explicitly reject Command Submission (CS) requests containing these fences. An attacker with local access could potentially exploit this to cause undefined behavior or kernel instability by submitting unsupported fence writes. The fix involves setting the 'no_user_fence' flag to true for the VCN v4.0.5 unified ring, ensuring such submissions are rejected. Patches have been backported to various stable kernel branches including 6.12.y, 6.18.y, and 7.0.y.
Affected products
- Linux Linux Kernel 6.7 to 7.1
Timeline
- 2026-07-19: disclosed: CVE-2026-63851 published by NVD
- 2026-04-28: patched: Initial fix committed to the Linux kernel tree