Improper input validation in Linux kernel - CVE-2026-63856
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in VCN v2.0 encoder and decoder rings when processing command submission requests with user fences. A local user can submit a crafted command stream with a user fence to cause a denial of service.
The issue affects VCN v2.0 encoder and decoder rings because they do not support 64-bit user fence writes.
How to mitigate CVE-2026-63856
Sources
- https://git.kernel.org/stable/c/5e777bc4cbe928ac0fd95e368fee1540f2ce4db2
- https://git.kernel.org/stable/c/8d80b293b41fcb5e9396db93e788b0f4ebcbafb7
- https://git.kernel.org/stable/c/ac06ce5cac9e711281585d09d00c6efcd9b86396
- https://git.kernel.org/stable/c/c71aecae98e42dcf2baf462df50b3a2cf1a93fe4
- https://git.kernel.org/stable/c/f264019be80de79f84f464846451445923bffea0