Impact
The flaw involves the AMDGPU VCN encoder writes. This leads the kernel to reject command submissions that include such fences, potentially causing applications that rely on the GPU to malfunction or terminate. The weakness corresponds to CWE-1287, reflecting the improper execution of a program component due to incorrect input handling.
Affected Systems
The vulnerability targets Linux kernel builds containing the AMDGPU VCN module for hardware version 5.0.1. It applies to all Linux distributions that ship this kernel code without the upstream patch, regardless of vendor.
Risk and Exploitability
The CVSS score of 7.8 conveys a high severity, while the EPSS score of less than 1% indicates that exploitation attempts are expected to be rare. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires local privileged access to inject GPU commands; it does not provide a remote attack vector and would likely result in command submission failure or a denial of service for the affected process.
OpenCVE Enrichment
Ubuntu USN