CVE-2026-63848

Source
https://cve.org/CVERecord?id=CVE-2026-63848
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63848.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63848
Downstream
Published
2026-07-19T14:04:40.798Z
Modified
2026-07-21T03:47:33.920262154Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/jpeg: set nouserfence for JPEG v2.0 ring

JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences.

(cherry picked from commit 96179da0c6b059eb31706a0abe8dd6381c533143)

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63848.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6ac27241106bc946bd50032f4cd96899c6a6fe69
Fixed
f675801889b265634aefd30aa4503fc2b9e6ce1c
Fixed
2e216c2ff159b2eb1da6e9c716d727efc73c64b5
Fixed
b41248d1c18384835f6532e68592ee07605da283
Fixed
41c4f3f68a343d62bd352a95ace93a11c4ad92ed
Fixed
e5f612dc91650561fe2b5b76dd6d2898ec9ad480

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63848.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.6.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63848.json"