Bug 2507218 (CVE-2026-64507) - CVE-2026-64507 kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation
Summary: CVE-2026-64507 kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation
Keywords:
Status: NEW
Alias: CVE-2026-64507
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-25 10:11 UTC by OSIDB Bzimport
Modified: 2026-09-30 15:43 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-25 10:11:14 UTC
In the Linux kernel, the following vulnerability has been resolved:

x86/bugs: Enable IBPB flush on BPF JIT allocation

Enable hardening against JIT spraying when Spectre-v2 mitigations are in
use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip
enabling the IBPB flush if the BPF dispatcher is already using a retpoline
sequence.

This hardening applies only when BPF-JIT is in use. Guard the enabling
under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.

Comment 3 Akiyoshi Kurita 2026-09-30 03:03:24 UTC
Additional information:

The BTR (Branch Target Reuse) research and Linux cBPF end-to-end exploit have now been publicly released:

https://github.com/vusec/btr

oss-security disclosure:
https://www.openwall.com/lists/oss-security/2026/09/30/1

The public repository includes an end-to-end exploit against the Linux cBPF JIT.

The published research demonstrates recovery of the root password hash from privileged memory within minutes on an Intel Linux system. This shows that the issue can result in practical disclosure of highly sensitive privileged data rather than being only a theoretical Spectre-v2 hardening issue.

CVE-2026-64507 enables an IBPB flush on BPF JIT memory reuse when the relevant Spectre-v2 mitigations are in use.

Relevant stable kernel fixes include:

RHEL 7 - RHEL 9 relevant stable commit:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=cb27f3bf915cc0f20fc0c48da9059304e39ebd35

RHEL 10 relevant stable commit:
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9354248fc1c33a844ca1872761f6668b393e8c37

Red Hat CVE page:
https://access.redhat.com/security/cve/cve-2026-64507

Given the availability of a practical end-to-end exploit and demonstrated disclosure of the root password hash, could Red Hat please re-evaluate the current impact and fix priority for this CVE?

Could Red Hat also confirm:

- whether affected RHEL 7, 8, 9, and 10 kernels have been tested against the public BTR exploit;
- whether the above fixes, or equivalent Red Hat backports, are present or planned for the affected RHEL kernel branches;
- whether the demonstrated arbitrary/sensitive memory disclosure primitive could facilitate a local privilege escalation chain when combined with other attack primitives.

The public exploit does not by itself demonstrate a complete LPE, but the ability of an unprivileged attacker to recover sensitive privileged memory warrants evaluation of possible privilege-escalation chains.


Note You need to log in before you can comment on or make changes to this bug.