Linux Kernel AMDGPU VCN User Fence Vulnerability in Encoder/Decoder Rings

Vulnerability

A vulnerability in the Linux kernel's AMDGPU VCN version 2.5 encoder and decoder rings has been addressed. These rings do not support 64-bit user fence writes and previously rejected command stream submissions that included user fences. The vulnerability has been resolved by modifying the ring functions to disable user fence support, ensuring compatibility with the hardware's capabilities.

Impact

The vulnerability could lead to improper handling of command stream submissions, potentially causing synchronization issues or allowing commands to be processed incorrectly.

Reproduction

The vulnerability can be reproduced by submitting command streams to the VCN v2.5 encoder or decoder rings with 64-bit user fences. The rings will reject the submission due to the unsupported user fence writes.

Remediation

Users can update to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the Linux kernel's official website.

Added: Jul 19, 2026, 3:34 PM
Updated: Jul 19, 2026, 3:34 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
3.9
remediation
7.7
relevance
9.7
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.