Junglewise Threat Intelligence

CVE-2026-63852: Linux Kernel AMDGPU unsupported user fence in VCN v4.0.3

CVE-2026-63852 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's AMD GPU driver affecting systems with VCN 4.0.3 hardware. The Video Codec Next (VCN) component, which handles video encoding and decoding, incorrectly allowed certain memory synchronization requests (user fences) that the hardware does not support. This could lead to unpredictable system behavior or stability issues when processing video tasks.

Technical details

In the Linux kernel's amdgpu driver, the VCN (Video Codec Next) v4.0.3 encoder and decoder rings do not support 64-bit user fence writes. Prior to this fix, the driver did not explicitly reject Command Submission (CS) requests containing these user fences. An attacker or a malicious local process could potentially exploit this lack of validation to trigger undefined hardware behavior or kernel instability. The fix involves setting the 'no_user_fence' flag to true for the VCN v4.0.3 unified ring functions, ensuring such submissions are rejected. Patches have been backported to several stable kernel branches including 6.6.y, 6.12.y, 6.18.y, and 7.0.y.

Affected products

  • Linux Linux 6.5 to 7.0.10

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References