Executive brief
A vulnerability was identified in the Linux kernel's AMD GPU driver where certain video encoding and decoding components (VCN v2.5) incorrectly handled specific memory synchronization requests. This could potentially lead to system instability or memory corruption when processing video data. The issue has been resolved by ensuring the driver rejects unsupported synchronization requests from user applications.
Technical details
A vulnerability in the Linux kernel's DRM subsystem for AMD GPUs (amdgpu) was discovered in the VCN (Video Core Next) v2.5 component. The VCN encoder and decoder rings do not support 64-bit user fence writes; however, the driver previously allowed Command Stream (CS) submissions that included these fences. An attacker with local access to the GPU device could potentially trigger memory corruption or a system crash by submitting malformed CS requests. The fix involves setting the 'no_user_fence' flag to true for VCN v2.5 rings, causing the kernel to reject such submissions. Patches are available in various stable kernel branches including 6.6.y, 6.12.y, 6.18.y, and 7.0.y.
Affected products
- Linux Linux 5.4 to 6.6.140, 6.12.90, 6.18.32, 7.0.9
Timeline
- 2026-07-19: disclosed
- 2026-07-19: advisory
References
- https://git.kernel.org/stable/c/2c6fb056567efb49f8674108b86088a1cfaa86d0
- https://git.kernel.org/stable/c/4f317863a3ab212a027d8c8c3cc3af4e3fb95704
- https://git.kernel.org/stable/c/5a3c6f76cab164a5d803084908d7050f649ab7f9
- https://git.kernel.org/stable/c/602d4c5872b25ddd4d82fb2025efb9a05b187bb3
- https://git.kernel.org/stable/c/8f0ea4524dc71c6c9ec97f2711f46e12f624140f