Impact
The vulnerability resides in the Linux kernel AMDGPU VCN driver not support these writes, any command submission that includes a user fence is rejected. This flaw stops GPU command streams from executing, which can make applications that rely on VCN encoding or decoding inoperable, effectively causing a denial of service for those processes. The weakness is a fault in the driver’s handling of user‑provided data, identified as CWE‑1287.
Affected Systems
Affected systems are Linux kernel environments that use the AMDGPU VCN driver. All Linux distributions running kernel versions that have not incorporated the fix from commit ff1a5a125c5a70c328806b9bc01d7d942cf3f9aa are vulnerable. The product is the Linux kernel; no specific distribution or kernel version list is provided beyond the presence of the VCN encoder ring.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1% indicates that exploitation is unlikely and it is not listed in CISA’s KEV catalog. A command stream that includes a user fence to the AMDGPU driver would trigger the flaw, but without such capability an attacker cannot exploit the flaw. If an attacker succeeds, the impact is denial of service for GPU‑accelerated workloads on the affected machine. Because no public exploit is known but the fix is recommended.
OpenCVE Enrichment
Ubuntu USN