CVE-2026-63854: Linux

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 663bed3c7b8b9a7624b0d95d300ddae034ad0614)

Affected products

  • Linux Linux: from 5.9, before 6.6.141 (fixed in 6.6.141); from 6.7, before 6.12.91 (fixed in 6.12.91); from 6.13, before 6.18.33 (fixed in 6.18.33); from 6.19, before 7.0.10 (fixed in 7.0.10)

Published 2026-07-19. Last modified 2026-07-27.