Skip to finding
§
High
Research — privilege
Confirmed
CVE-2026-64507

Branch Target Reuse lets an unprivileged Linux process read arbitrary host memory despite deployed Spectre-v2 defenses.

Public artifacts demonstrate the cross-privilege break end to end.

Affects

The Linux kernel cBPF JIT on x86 systems, demonstrated on stock Ubuntu 24.04.

What it enables

Cross-privilege disclosure of arbitrary host memory from an unprivileged process

Run unprivileged native code and install cBPF filters through seccomp or Linux socket filtering.→↓Train the cBPF dispatcher’s indirect branch, free the JIT allocation and force controlled reuse of its address.→↓Reuse the stale branch-predictor target to enter newly generated code at an obsolete or misaligned offset.→↓Reach a speculative disclosure gadget, recover KASLR state and follow kernel aliases into arbitrary process memory.→↓Recover the root password hash from a live su process in an average of three to five minutes on the demonstrated Intel systems.
Why this matters

Deployed Spectre-v2 defenses no longer close this path: public artifacts demonstrate arbitrary host-memory recovery from an unprivileged process.

Detail, proof-of-concept code and 5 sources
Required access

Unprivileged native code execution on an affected Intel Linux host with the cBPF JIT available

Affected versions

Linux kernel 5.18 and later before the applicable stable backport, Demonstrated on Ubuntu 24.04 kernel 6.14.0-27, SpiderMonkey and GraalVM expose the underlying reuse primitive, but the paper does not demonstrate equivalent end-to-end disclosure there

Proof of concept

Public exploit code →

An unprivileged process that can install cBPF filters trains the dispatcher, frees its JIT allocation and forces controlled address reuse; a stale indirect-branch prediction then enters newly generated code at an obsolete or misaligned offset.

The demonstrated chain recovers KASLR state, follows kernel aliases into arbitrary process memory and extracts a live su process's root password hash in an average of three to five minutes on the tested systems.

The upstream Linux mitigation issues an indirect branch prediction barrier when a JIT allocation is reused.

Evidence
The ACM CCS paper demonstrates two end-to-end cBPF exploits and arbitrary process-data recovery on stock Ubuntu.The public VUSec repository contains the microarchitectural experiments, attack-surface analysis and Linux end-to-end exploit artifacts.The upstream Linux CVE record identifies affected ranges, fixes and the IBPB-on-JIT-reuse mitigation.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026