Linux patches two Spectre-style flaws in the kernel's BPF engine

Kernel maintainers shipped fixes for CVE-2026-64507 and CVE-2026-64508 after researchers showed old branch predictions could leak data from new code.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal close-up of a modern server-class CPU die on a green motherboard, soft blue rim light, shallow depth of field, faint red glow
Share

Key points

  • Linux kernel maintainers assigned CVE-2026-64507 and CVE-2026-64508, covering a Spectre-v2 weakness in the kernel's BPF just-in-time engine.
  • Fixes landed in stable kernel releases, with versions confirmed in the patch series for the 6.6, 6.12 and 6.18 branches.
  • VUSec and Scuola Superiore Sant'Anna disclosed the technique, calling it Branch Target Reuse, or BTR.
  • The kernel now issues an indirect branch predictor flush, called IBPB, whenever BPF JIT memory is reused.
  • No exploitation in the wild has been reported by the kernel CVE team.

Linux has patched a pair of processor-level weaknesses that let an attacker already running code on a machine read memory they shouldn't see.

The fixes, published by stable kernel maintainer Greg Kroah-Hartman, cover CVE-2026-64507 and CVE-2026-64508. Both sit inside BPF, a small in-kernel engine that runs sandboxed programs for network filtering and performance tracing.

The underlying problem is a new twist on Spectre, the family of CPU flaws first disclosed in 2018. Researchers at VUSec in Amsterdam and Scuola Superiore Sant'Anna in Italy named this variant Branch Target Reuse, or BTR, and The Hacker News first reported the academic disclosure. As we wrote on 24 September, dozens of Spectre variants keep arriving seven years on from the original disclosures.

What actually goes wrong?

Old predictions the CPU made for one program can steer another program that later occupies the same memory, and that's the leak BTR exploits.

Modern chips guess where code will jump next. That guess is called a branch prediction. The kernel's BPF just-in-time compiler turns small BPF programs into native machine code, packing many of them into shared blocks of executable memory. When one program is unloaded and another takes its slot, the CPU may still hold the old prediction. An attacker controlling the new program can nudge the CPU into following that stale prediction and read bits of kernel memory in the process.

How does the fix work?

The patches force the CPU to discard its indirect branch predictions before BPF memory is reused. On Intel and AMD systems that means issuing IBPB, short for Indirect Branch Prediction Barrier, whenever the JIT allocator hands out space that held a different program.

A second patch adds a generic hook so other CPU architectures can plug in their own flush routine. If a system already uses a slower software mitigation called a retpoline for its BPF dispatcher, the kernel skips the extra flush.

Which kernels are fixed?

CVE Issue Fixed branches
CVE-2026-64507 IBPB flush on BPF JIT allocation 6.6, 6.12, 6.18
CVE-2026-64508 Generic BPF JIT spraying hardening 6.6, 6.12, 6.18

Distributions that ship long-term kernels, including Debian, Ubuntu, Red Hat Enterprise Linux and SUSE, will pull these patches into their own updates over the coming days. Servers and cloud hosts that run untrusted BPF programs, mostly shared hosting and container platforms, are the practical targets here.

What should ordinary users do?

Apply the update your Linux distribution offers and reboot. Desktop users are unlikely to be attacked through this route because it requires local code execution. Cloud tenants and anyone running Kubernetes or similar shared infrastructure should push the patched kernel out sooner.

Spectre-class bugs haven't gone away. The MIT CSAIL interrupt-injection technique we reported on 6 August showed attackers can re-poison the branch predictor even after a flush; BTR shows they can skip the flush entirely by recycling memory. Seven years on, the hardware fix still isn't close. Kernel developers are doing the cleanup work chip vendors have not.

© 2026 Threat Vectr