CVE-2026-64507

Source
https://cve.org/CVERecord?id=CVE-2026-64507
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64507.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64507
Downstream
Published
2026-07-25T08:52:01.008Z
Modified
2026-07-28T04:03:08.650191420Z
Summary
x86/bugs: Enable IBPB flush on BPF JIT allocation
Details

In the Linux kernel, the following vulnerability has been resolved:

x86/bugs: Enable IBPB flush on BPF JIT allocation

Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence.

This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIGBPFJIT so that bugs.c still builds with CONFIGBPFJIT=n.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64507.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
57631054fae6dcc9c892ae6310b58bbb6f6e5048
Fixed
cb27f3bf915cc0f20fc0c48da9059304e39ebd35
Fixed
9354248fc1c33a844ca1872761f6668b393e8c37
Fixed
8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1
Fixed
52440e15d9628f8f239373c0f2e5e8f92feea2df
Fixed
a3af84b0fa00ead01fcd0e28b5d773ff25990a0d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64507.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64507.json"