CVE-2026-63847

7.8

Linux · Kernel

A vulnerability in the Linux kernel amdgpu JPEG driver allows local authenticated users to cause high impacts on confidentiality, integrity, and availability.

Executive summary

A high-severity vulnerability in the Linux kernel amdgpu JPEG driver allows local users to achieve full system compromise by exploiting improper handling of user fences.

Vulnerability

This is an improper control handling flaw in the amdgpu JPEG driver ring implementation, requiring local access with low privileges and no user interaction.

Business impact

A successful exploit of this vulnerability can lead to complete compromise of the affected host system, including unauthorized data access, system modification, and denial of service. The CVSS score of 7.8 indicates a high severity rating, reflecting that while local access is required, the resulting impact on confidentiality, integrity, and availability is critical.

Remediation

Immediate Action: Update the Linux kernel to version 6.6.141, 6.12.91, 6.18.33, 7.0.10, or later depending on the active release branch.

Proactive Monitoring: Monitor system logs for unauthorized local shell access and unexpected kernel crashes or panics related to the amdgpu driver.

Compensating Controls: Restrict local shell access and enforce strict the principle of least privilege to prevent untrusted users from executing arbitrary commands or code on the host.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Administrators must prioritize updating the Linux kernel across all affected systems to remediate the underlying driver flaw. Given the high severity score and potential for full system compromise, prompt patching is essential to maintain environmental security.

More Linux CVEs

Sources