CVE-2026-63841

7.8

Linux · Kernel

A vulnerability in the Linux kernel DRM amdgpu JPEG driver allows local attackers with low privileges to achieve high confidentiality, integrity, and availability impacts due to missing user fence checks on JPEG v5.0.1 rings.

Executive summary

A high severity vulnerability in the Linux kernel amdgpu JPEG driver permits local privilege escalation and system compromise through improper handling of user fence writes.

Vulnerability

This is a driver-level memory management flaw in the Direct Rendering Manager subsystem, specifically within the AMD GPU JPEG module, requiring low local privileges and no user interaction to execute.

Business impact

A successful exploit of this vulnerability could grant a local attacker complete control over the affected host system, leading to full data compromise, unauthorized access, and potential denial of service. The CVSS score of 7.8 reflects a high severity rating due to the high impact on system confidentiality, integrity, and availability despite requiring local access.

Remediation

Immediate Action: Update the Linux kernel to version 6.18.33, 7.0.10, or later where the fix is incorporated.

Proactive Monitoring: Monitor system logs for unusual local user activity, kernel panics, or graphics driver faults associated with the amdgpu module.

Compensating Controls: Restrict local shell access and tightly control user permissions on systems utilizing vulnerable AMD GPU hardware configurations.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Administrators must prioritize updating the Linux kernel to the patched versions to eliminate local attack vectors against the graphics subsystem. Applying the latest stable kernel builds is critical to maintaining system security and preventing potential local privilege escalation.

More Linux CVEs

Sources