Junglewise Threat Intelligence

CVE-2026-63854: Linux Kernel AMDGPU unsupported user fence in VCN v3.0

CVE-2026-63854 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's AMD GPU driver affecting systems with VCN 3.0 hardware. The video encoding and decoding components were incorrectly allowing certain memory synchronization requests (user fences) that the hardware does not actually support. This could lead to unpredictable system behavior or stability issues when processing video data.

Technical details

A vulnerability in the 'amdgpu' driver within the Linux kernel stems from the VCN (Video Core Next) v3.0 encoder and decoder rings incorrectly handling 64-bit user fence writes. The hardware does not support these operations, but the driver previously did not explicitly block them during Command Submission (CS). An attacker with local access could potentially exploit this to cause undefined behavior or kernel instability by submitting CS requests with user fences. The fix involves setting the 'no_user_fence' flag to true for VCN v3.0 rings to ensure such submissions are rejected.

Affected products

  • Linux Linux 5.9 to 7.0.10

Timeline

  • 2026-07-19: disclosed
  • 2026-07-19: advisory

References