CVE-2026-63852

HIGHCVSS 7.8/10EPSS 0.12%

Last modified

CVE-2026-63852 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit ff1a5a125c5a70c328806b9bc01d7d942cf3f9aa). EPSS estimates a 0.12% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit ff1a5a125c5a70c328806b9bc01d7d942cf3f9aa)

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.12%

2.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b889ef4ac98837838c38f7b9f72bba2f33ee367d, < c12a5d35033c0640c57c10d7111c010c7b9c2c8e; >= b889ef4ac98837838c38f7b9f72bba2f33ee367d, < 387b7c7667bd5c53549350ddad866d2fcf75a529; >= b889ef4ac98837838c38f7b9f72bba2f33ee367d, < 9076a83e5adefd10dc5c967c7b8bde601c4c512a; >= b889ef4ac98837838c38f7b9f72bba2f33ee367d, < 0177ac6141c8857130cf365369c74dee7b6b1f7f; >= b889ef4ac98837838c38f7b9f72bba2f33ee367d, < 4532b52b34e4e4310386e6fdf6a643368599f522
LinuxLinux6.5

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2026-63852?
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit ff1a5a125c5a70c328806b9bc01d7d942cf3f9aa)
How severe is CVE-2026-63852?
CVE-2026-63852 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.12% probability of exploitation in the next 30 days.
How do I fix CVE-2026-63852?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-63852?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST