Find notable cyber news and cases, enriched with sources, timelines, and signals.

Linux kernel security patch release for CVE-2026-64507

Security Patch Release
First reported
Last updated
Happening score
H score 24
2 unique sources, 2 articles

Summary

Hide ▲

Mitigations for Branch Target Reuse (BTR) have been released and merged into the Linux kernel, delivering fixes for CVE-2026-64507 and CVE-2026-64508. The update addresses a Spectre-v2 variant that targets JIT engines across browsers, language runtimes, and the operating system kernel. The release follows responsible disclosure after proof-of-concept work showed root password hash leakage on a fully patched Intel system.

Related Happenings

CISA adds Linux kernel flaws to KEV catalog under BOD 26-04

Public Sector Action
H score36 First: 19.09.2026 09:24 Last: 19.09.2026 09:24 Sources 1

About this happening: CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...

Red Hat Linux kernel advisory update for active exploitation

Advisory/Mitigation
H score53 First: 19.09.2026 09:24 Last: 19.09.2026 09:24 Sources 1

About this happening: Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pu...

Linux stable kernel maintainers security patch release for CVE-2026-64564

Security Patch Release
H score28 First: 07.08.2026 14:10 Last: 07.08.2026 14:10 Sources 1

About this happening: Linux stable kernels shipped fixes for CVE-2026-64564, closing an SCTP use-after-free that could give local users root on hosts with SCTP reachable. The patched bu...

INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux

Technical Analysis
H score24 First: 06.08.2026 19:17 Last: 06.08.2026 19:17 Sources 1

About this happening: MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to s...

Linux kernel upstream security patch release for CVE-2026-53264

Security Patch Release
H score32 First: 28.07.2026 11:04 Last: 28.07.2026 11:04 Sources 1

About this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...

Timeline

  1. 29.09.2026 20:00 2 articles · 1h ago

    Linux kernel merges BTR mitigations for CVE-2026-64507 and CVE-2026-64508

    Mitigation Patch Update

    Mitigations for Branch Target Reuse (BTR), a Spectre-v2 variant that targets JIT engines in web browsers, language runtimes, and the Linux kernel across multiple CPU vendors, were released and merged into the Linux kernel for CVE-2026-64507 and CVE-2026-64508 after responsible disclosure.

    Show sources