Protection mechanism failure in Linux kernel - CVE-2026-64508
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass branch prediction isolation for reused BPF JIT memory.
The vulnerability exists due to improper isolation of indirect branch predictor state in the BPF JIT allocator when reusing JIT memory for newly written programs. A remote attacker can load and free BPF programs to bypass branch prediction isolation for reused BPF JIT memory.
Allocations larger than a pack are not covered by this condition, and the described attack surface is limited to cBPF programs that fit within pack size constraints.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64508
linux (Debian package) - update to 6.12.100-1
External References
- https://git.kernel.org/stable/c/6e52c240c43a601b681e3a4e58fc5685114d4726
- https://git.kernel.org/stable/c/7a6c171c6a1ac6d1509752dac131d941a3de0b37
- https://git.kernel.org/stable/c/8ff183ee4d8c452960df58175a094828c0513b2e
- https://git.kernel.org/stable/c/96cce16e26dd02a8678f1e87f88a4b5cdb63b995
- https://git.kernel.org/stable/c/eed774da601268dae674e14d54a15e3624691f52