Linux kernel security patch release for CVE-2026-64507
Security Patch Release
Summary
Hide ▲
Show ▼
Mitigations for Branch Target Reuse (BTR) have been released and merged into the Linux kernel, delivering fixes for CVE-2026-64507 and CVE-2026-64508. The update addresses a Spectre-v2 variant that targets JIT engines across browsers, language runtimes, and the operating system kernel. The release follows responsible disclosure after proof-of-concept work showed root password hash leakage on a fully patched Intel system.
Related Happenings
CISA adds Linux kernel flaws to KEV catalog under BOD 26-04
Public Sector Action
H score36
First: 19.09.2026 09:24
Last: 19.09.2026 09:24
Sources 1
About this happening:
CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...
CISA adds Linux kernel flaws to KEV catalog under BOD 26-04
Public Sector ActionAbout this happening: CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...
Red Hat Linux kernel advisory update for active exploitation
Advisory/Mitigation
H score53
First: 19.09.2026 09:24
Last: 19.09.2026 09:24
Sources 1
About this happening:
Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pu...
Red Hat Linux kernel advisory update for active exploitation
Advisory/MitigationAbout this happening: Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pu...
Linux stable kernel maintainers security patch release for CVE-2026-64564
Security Patch Release
H score28
First: 07.08.2026 14:10
Last: 07.08.2026 14:10
Sources 1
About this happening:
Linux stable kernels shipped fixes for CVE-2026-64564, closing an SCTP use-after-free that could give local users root on hosts with SCTP reachable. The patched bu...
Linux stable kernel maintainers security patch release for CVE-2026-64564
Security Patch ReleaseAbout this happening: Linux stable kernels shipped fixes for CVE-2026-64564, closing an SCTP use-after-free that could give local users root on hosts with SCTP reachable. The patched bu...
INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux
Technical Analysis
H score24
First: 06.08.2026 19:17
Last: 06.08.2026 19:17
Sources 1
About this happening:
MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to s...
INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux
Technical AnalysisAbout this happening: MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to s...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch Release
H score32
First: 28.07.2026 11:04
Last: 28.07.2026 11:04
Sources 1
About this happening:
Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch ReleaseAbout this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Timeline
-
29.09.2026 20:00 2 articles · 1h ago
Linux kernel merges BTR mitigations for CVE-2026-64507 and CVE-2026-64508
Mitigation Patch UpdateMitigations for Branch Target Reuse (BTR), a Spectre-v2 variant that targets JIT engines in web browsers, language runtimes, and the Linux kernel across multiple CPU vendors, were released and merged into the Linux kernel for CVE-2026-64507 and CVE-2026-64508 after responsible disclosure.
Show sources
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses — thehackernews.com — 29.09.2026 20:00
- New Spectre v2 attack variant leaks Linux root password hash in minutes — www.bleepingcomputer.com — 29.09.2026 20:10