CVE-2026-64507

Source
https://cve.org/CVERecord?id=CVE-2026-64507
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64507.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64507
Downstream
Related
Published
2026-07-25T08:52:01Z
Modified
2026-08-21T03:30:18Z
Summary
x86/bugs: Enable IBPB flush on BPF JIT allocation
Details

In the Linux kernel, the following vulnerability has been resolved:

x86/bugs: Enable IBPB flush on BPF JIT allocation

Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence.

This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64507.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
57631054fae6dcc9c892ae6310b58bbb6f6e5048
Fixed
25dbcd31781e2bc3cd63d873af1fcd06f863a126
Fixed
cb27f3bf915cc0f20fc0c48da9059304e39ebd35
Fixed
9354248fc1c33a844ca1872761f6668b393e8c37
Fixed
8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1
Fixed
52440e15d9628f8f239373c0f2e5e8f92feea2df
Fixed
a3af84b0fa00ead01fcd0e28b5d773ff25990a0d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64507.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64507.json"