Executive brief
A vulnerability in the Linux kernel's BPF (Berkeley Packet Filter) component could allow an attacker to influence how the system predicts future code execution. By loading and unloading small programs, an attacker could potentially trick the system into incorrectly jumping to malicious code based on 'leftover' predictions from previous programs. This type of issue, known as JIT spraying, can be used to bypass security protections and gain unauthorized control over the operating system.
Technical details
A vulnerability in the Linux kernel's BPF JIT allocator allowed for potential JIT spraying attacks due to the reuse of executable memory without flushing branch predictors. The allocator packs multiple small BPF programs into larger executable pages; when a program is freed and a new one is written to the same location, indirect jumps in the new program could reuse branch prediction entries left by the old program. This could be exploited by unprivileged users (via cBPF) to influence speculative execution or redirect control flow. The fix introduces a mechanism to flush indirect branch predictors (bpf_arch_pred_flush) specifically when JIT memory is being reused within a pack.
Affected products
- Linux Linux Kernel versions before 6.6.145, 6.12.97, 6.18.39, 7.1.4
Timeline
- 2026-07-25: advisory: CVE-2026-64508 published by NVD
- 2026-07-24: patched: Fix committed to stable kernel trees
References
- https://git.kernel.org/stable/c/6e52c240c43a601b681e3a4e58fc5685114d4726
- https://git.kernel.org/stable/c/7a6c171c6a1ac6d1509752dac131d941a3de0b37
- https://git.kernel.org/stable/c/8ff183ee4d8c452960df58175a094828c0513b2e
- https://git.kernel.org/stable/c/96cce16e26dd02a8678f1e87f88a4b5cdb63b995
- https://git.kernel.org/stable/c/eed774da601268dae674e14d54a15e3624691f52