CVE-2026-63854

Source
https://cve.org/CVERecord?id=CVE-2026-63854
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63854.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63854
Downstream
Published
2026-07-19T14:04:44.487Z
Modified
2026-07-22T05:29:53.042635826Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings
Details

In the Linux kernel, the following vulnerability has been resolved:

drm/amdgpu/vcn: set nouserfence for VCN v3.0 enc/dec rings

VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences.

(cherry picked from commit 663bed3c7b8b9a7624b0d95d300ddae034ad0614)

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63854.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
cf14826cdfb5c9fe10f98210d040b9d7486c381d
Fixed
e74fc9c72c1ba78d0de0b849f5929c3b39a8e20c
Fixed
26c4f38529ac78930c9c4713e16ebc5b689bb0a3
Fixed
2d6525e7b2504f5bbfe9417cddc1e8da858791dd
Fixed
b076e45e6f757a2829e80d0144c1b5f201bee5af
Fixed
f1e5a6660d7cbf006079126d9babbf0ccf538c6b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63854.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.9.0
Fixed
6.6.141
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.91
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.33
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63854.json"