CVE-2026-63842

7.8

Linux · Kernel

A vulnerability in the Linux kernel amdgpu JPEG driver allows local users with low privileges to impact confidentiality, integrity, and availability.

Executive summary

A local privilege escalation and denial of service vulnerability in the Linux kernel amdgpu JPEG driver allows low-privileged attackers to achieve full system compromise.

Vulnerability

This is an improper handling of user fence writes within the DRM AMDGPU JPEG driver, where JPEG v5.0.0 rings fail to support 64-bit user fence writes and do not correctly reject command stream submissions containing them, requiring low privileges and no user interaction.

Business impact

Successful exploitation of this vulnerability allows a local attacker with low privileges to gain complete control over the affected operating system, leading to confidentiality breaches, data tampering, and severe system downtime. The CVSS score of 7.8 reflects the high severity of potential impacts on system confidentiality, integrity, and availability.

Remediation

Immediate Action: Update the Linux kernel to version 6.12.91, 6.18.33, 7.0.10, or later where the patch is integrated.

Proactive Monitoring: Monitor local system logs for unauthorized command submission attempts, abnormal driver crashes, or unexpected kernel panics related to the amdgpu driver.

Compensating Controls: Restrict local shell access and limit user privileges to trusted accounts only, reducing the pool of actors who can leverage the local attack vector.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score and the deep operating system access granted by kernel-level flaws, prompt action is required to secure vulnerable infrastructure. System administrators must prioritize patching the Linux kernel to the fixed versions across all applicable host environments to neutralize the risk of local compromise.

More Linux CVEs

Sources