Impact
A Linux kernel defect in the AMDGPU Virtual Codec Engine (VCN) board limits the handling of 64‑bit user fence writes. The kernel incorrectly rejects command streams that include such fences for the VCN v4.0 encoder and decoder rings, causing the driver to fail to process the submission and potentially disabling GPU functionality. This results in a denial of service for GPU operations. The weakness is identified as CWE‑1287, an input validation flaw.
Affected Systems
All Linux kernel versions that ship the AMDGPU driver with support for the VCN v4.0 encoder and decoder rings are affected. The issue is confined to AMD GPU hardware GPU drivers or hardware are not impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score of <1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV is local, where a user with access to the GPU device can submit the denial of service. No remote or privilege‑escapable exploitation is described in the available information.
OpenCVE Enrichment
Ubuntu USN