Linux Kernel Vulnerability Affecting BPF JIT Allocation
CVE-2026-64507
What is CVE-2026-64507?
A vulnerability in the Linux kernel has been identified which affects the BPF Just-In-Time (JIT) allocation. The issue involves a potential exploitation vector related to JIT spraying while mitigating the Spectre version 2 attack. To enhance security, the introduction of an Indirect Branch Predictors Barrier (IBPB) flush on BPF JIT memory reuse has been implemented. This hardening mechanism is conditionally activated based on the usage of BPF JIT, ensuring that even when this feature is not employed, the integrity of the kernel code remains intact. Proper configuration is necessary to enable these protective measures.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9354248fc1c33a844ca1872761f6668b393e8c37
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1