Fedora Account System
Red Hat Associate
Red Hat Customer
In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence. This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2026072554-CVE-2026-64507-5288@gregkh/T
Additional information: The BTR (Branch Target Reuse) research and Linux cBPF end-to-end exploit have now been publicly released: https://github.com/vusec/btr oss-security disclosure: https://www.openwall.com/lists/oss-security/2026/09/30/1 The public repository includes an end-to-end exploit against the Linux cBPF JIT. The published research demonstrates recovery of the root password hash from privileged memory within minutes on an Intel Linux system. This shows that the issue can result in practical disclosure of highly sensitive privileged data rather than being only a theoretical Spectre-v2 hardening issue. CVE-2026-64507 enables an IBPB flush on BPF JIT memory reuse when the relevant Spectre-v2 mitigations are in use. Relevant stable kernel fixes include: RHEL 7 - RHEL 9 relevant stable commit: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=cb27f3bf915cc0f20fc0c48da9059304e39ebd35 RHEL 10 relevant stable commit: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=9354248fc1c33a844ca1872761f6668b393e8c37 Red Hat CVE page: https://access.redhat.com/security/cve/cve-2026-64507 Given the availability of a practical end-to-end exploit and demonstrated disclosure of the root password hash, could Red Hat please re-evaluate the current impact and fix priority for this CVE? Could Red Hat also confirm: - whether affected RHEL 7, 8, 9, and 10 kernels have been tested against the public BTR exploit; - whether the above fixes, or equivalent Red Hat backports, are present or planned for the affected RHEL kernel branches; - whether the demonstrated arbitrary/sensitive memory disclosure primitive could facilitate a local privilege escalation chain when combined with other attack primitives. The public exploit does not by itself demonstrate a complete LPE, but the ability of an unprivileged attacker to recover sensitive privileged memory warrants evaluation of possible privilege-escalation chains.