Database/Kernel, userspace & hypervisor
Linux kernel BPF JIT: reused JIT memory can inherit branch predictions from the program that freed it
Impact
The BPF JIT packs many small programs into shared executable allocations and reuses that space as programs are loaded and freed. Before this fix, an indirect jump into freshly written code could resolve against a branch prediction left behind by the program that previously occupied the same address, which is the primitive behind JIT-spraying-style Spectre-v2 attacks. The fix adds a hook (static key plus static call) to flush indirect branch predictors before JIT memory is reused; the x86 side that actually enables it is CVE-2026-64507. On a GPU node packing several tenants' pods, unprivileged classic BPF - seccomp filters and socket filters are reachable from an ordinary container - is the attack surface the commit explicitly names as the unprivileged one. The record describes hardening, not a demonstrated exploit or a leak of specific data.
Who can reach it
Local. Any tenant that can run code on the node and load a BPF program, including unprivileged classic BPF via seccomp or socket filters. No elevated privileges and no network reachability required.
What to do
Update to a stable kernel carrying the listed commits and reboot. This is JIT-allocator plumbing plus a new static call, not the kind of narrow change usually shipped as a livepatch, so plan a drain and reboot per node rather than a hot patch. It has no effect on its own without the architecture enablement (CVE-2026-64507), so take both. If you cannot reboot promptly, disabling unprivileged BPF (kernel.unprivileged_bpf_disabled) narrows the unprivileged surface but does not remove it, since seccomp filters remain available.
References
Related entries
- Linux i915 GPU kernel driver (context SSEU parameter): NULL dereference reachable by setting a context engine slotCVE-2026-68243 · Linux i915 GPU kernel driver (context SSEU parameter)Unscored
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A correctness defect in the amdkfd (KFD computeCVE-2026-68259 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Unscored
- Linux kernel Intel IOMMU: out-of-bounds memset in dmar_latency_disable() corrupts adjacent memoryCVE-2026-68324 · Linux kernel Intel IOMMU (dmar_latency_disable)Unscored
- Linux kernel BPF sockmap: unhashed UDP sockets leak socket refcounts, exhausting host memoryCVE-2026-68386 · Linux kernel BPF sockmap (UDP socket refcount on map update)Unscored
- Linux kernel KVM x86 MMU: use-after-free when a vendor module is reloaded after a failed initCVE-2026-68428 · Linux kernel KVM x86 MMU (mmu_destroy_caches)Unscored
- Linux perf/x86/amd/brs - kernel address leakage through Branch Sampling: A user-only branch stack collected via AMDCVE-2026-72237 · Linux perf/x86/amd/brs - kernel address leakage through Branch SamplingUnscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.