SB2026072757 - Protection mechanism failure in Linux kernel bpf
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Protection mechanism failure (CVE-ID: CVE-2026-64508)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass branch prediction isolation for reused BPF JIT memory.
The vulnerability exists due to improper isolation of indirect branch predictor state in the BPF JIT allocator when reusing JIT memory for newly written programs. A remote attacker can load and free BPF programs to bypass branch prediction isolation for reused BPF JIT memory.
Allocations larger than a pack are not covered by this condition, and the described attack surface is limited to cBPF programs that fit within pack size constraints.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6e52c240c43a601b681e3a4e58fc5685114d4726
- https://git.kernel.org/stable/c/7a6c171c6a1ac6d1509752dac131d941a3de0b37
- https://git.kernel.org/stable/c/8ff183ee4d8c452960df58175a094828c0513b2e
- https://git.kernel.org/stable/c/96cce16e26dd02a8678f1e87f88a4b5cdb63b995
- https://git.kernel.org/stable/c/eed774da601268dae674e14d54a15e3624691f52