Impact
The Linux kernel's AMDGPU driver contains a flaw in the JPEG ring that mishandles 64‑bit user fence writes, causing command submission attempts with these fences to be rejected. This defect is classified as CWE‑1287 and can interrupt JPEG processing, resulting in a loss of GPU functionality for applications relying on hardware acceleration.
Affected Systems
Any Linux kernel that includes the AMDGPU driver with JPEG ring support prior to the inclusion of commit 0f43893d3cd478fa57836697525b338817c9c23d is potentially affected. This includes systems running recent mainstream distributions that ship the default amdgpu kernel module and use an AMDGPU GPU. Systems that do not use AMDGPU or have had the patch applied are not impacted.
Risk and Exploitability
The vulnerability receives a CVSS score of 7.8, indicating high severity, while the EPSS score of <1% suggests a very low likelihood of exploitation at present. The CVE is not listed in the CISA KEV catalog. Attackers would need local access to a system with an AMDGPU GPU; remote exploitation is not indicated, so the attack vector is inferred to be local.
OpenCVE Enrichment
Ubuntu USN