CVE-2026-63846

Source
https://cve.org/CVERecord?id=CVE-2026-63846
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63846.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63846
Downstream
Published
2026-07-19T14:04:39.674Z
Modified
2026-07-21T03:47:35.758640744Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/jpeg: set nouserfence for JPEG v3.0 ring

JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences.

(cherry picked from commit 4d7d774f100efb5089c86a1fb8c5bf47c63fc9ef)

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63846.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
dfd57dbf44ddc70c90c76f83b2deb46e5dd40ce3
Fixed
ee035a9d3eed3a9f5a3e83c31a10b321c9598861
Fixed
303da8279f195cc741adc52c1b44d6b64de63bb0
Fixed
5ada37d7f736f9feeaa06a25e470a4c74e67a61a
Fixed
48ce00787e3fddd2b45692fc991b8ab128343da5
Fixed
a2baf12eec41f246689e6a3f8619af1200031576

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63846.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.9.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63846.json"