CVE-2026-63850

7.8

Linux · Kernel

A vulnerability exists in the Linux kernel AMDGPU driver VCN encoder ring handling, which can be exploited locally by authenticated users to achieve high system impact.

Executive summary

A high severity vulnerability in the Linux kernel AMDGPU driver allows local attackers with low privileges to achieve complete system compromise through improper VCN encoder ring handling.

Vulnerability

This is a memory handling flaw in the drm/amdgpu/vcn component where VCN encoder and decoder rings do not support 64-bit user fence writes, requiring low privileges and no user interaction.

Business impact

A successful exploit of this vulnerability can lead to a complete compromise of confidentiality, integrity, and availability of the affected host system. Since the CVSS score is 7.8, it represents a high risk for local privilege escalation or system instability, potentially allowing an attacker with low-level local access to execute arbitrary code or trigger denial of service conditions.

Remediation

Immediate Action: Update the Linux kernel to version 6.12.91, 6.18.33, 7.0.10, or later where the fix is integrated.

Proactive Monitoring: Monitor local system logs for unusual kernel crashes, segmentation faults, or unauthorized attempts to interact with the AMDGPU graphics driver.

Compensating Controls: Restrict local shell access and audit user accounts to ensure only trusted personnel possess local access privileges.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators should treat this high severity kernel flaw with urgency by scheduling kernel updates during the next maintenance window. Applying the official stable kernel patches prevents potential local privilege escalation attacks stemming from improper VCN ring buffer and user fence management.

More Linux CVEs

Sources