CVE-2026-63851

7.8

Linux · Linux Kernel

A memory management flaw in the Linux kernel AMDGPU VCN driver allows local users to achieve high privileges.

Executive summary

A vulnerability in the Linux kernel AMDGPU driver allows authenticated local users to execute arbitrary code or cause a system crash.

Vulnerability

This vulnerability involves the improper handling of 64-bit user fence writes within the DRM AMDGPU VCN encoder and decoder rings, requiring low privileges and local access to exploit.

Business impact

A successful exploit of this vulnerability can lead to complete compromise of the affected host system, resulting in confidentiality, integrity, and availability losses. The CVSS score of 7.8 reflects the high severity of granting elevated local control, which could allow an attacker to escalate privileges, access sensitive data, or disrupt critical business services hosted on the machine.

Remediation

Immediate Action: Update the Linux kernel to version 6.12.91, 6.18.33, 7.0.10, or later depending on the active branch.

Proactive Monitoring: Monitor local system logs for unauthorized access attempts, unexpected privilege escalations, or kernel panic events related to the amdgpu module.

Compensating Controls: Restrict local shell access and implement strict principle-of-least-privilege controls to prevent unauthorized users from executing untrusted code on the host.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators must prioritize updating the Linux kernel across all vulnerable environments to mitigate the risk of local privilege escalation. Applying the official kernel patches immediately ensures that the improper VCN ring fence handling is resolved before local actors can weaponize the defect.

More Linux CVEs

Sources