News

BTR (CVE-2026-64507, CVE-2026-64508): Spectre v2 kernel flaw, CloudLinux patch status

CloudLinux confirms: all versions except CL7 are exposed to BTR, a Spectre v2 variant that reads kernel memory. No mitigation available, fix not yet released.

UptimeMag editorial team · 5 October 2026 · 2 min read

BTR (CVE-2026-64507, CVE-2026-64508): falla Spectre v2 nel kernel, stato patch CloudLinux

CloudLinux published a security advisory on 5 October 2026 (14:05 UTC) regarding BTR, a Spectre v2 variant identified with two CVEs: CVE-2026-64507 and CVE-2026-64508, rated Moderate by Red Hat. It affects anyone running shared hosting: an unprivileged local user, including a PHP worker behind a compromised WordPress plugin, can read kernel memory shared by all accounts on the machine.\n\nAccording to the CloudLinux advisory, all versions are affected except CloudLinux 7, because only on CL7 do BPF filters remain interpreted rather than compiled. A public proof-of-concept, released on 29 September 2026 by VUSec (VU Amsterdam) and Scuola Superiore Sant'Anna, works end-to-end only on two Intel microarchitectures, Raptor Cove and Lion Cove; on other Intel processors it needs adapting, while on AMD and Arm the researchers confirmed the behaviour but without a working exploit.\n\n## The bug and why it matters\n\nThe kernel's JIT compiles BPF filters (used by seccomp and socket filters) and reuses the memory once a programme is freed. The processor, however, retains indirect branch predictions for that address, and a new programme loaded into the same slot can cause hidden code to be speculatively executed. The attack reads memory at roughly 8 bytes per second, according to the advisory: too slow for a bulk dump, but enough to recover the root password hash from a running su process in 3-5 minutes. The hash still needs to be cracked offline: BTR does not grant root on its own.\n\n## Mitigations: none\n\nCloudLinux states that neither net.core.bpf_jit_harden nor kernel.unprivileged_bpf_disabled block the attack, since the payload hides within jump distances and the filters still pass through seccomp or socket filters regardless.\n\n## Patch status by version, as of 5 October 2026\n\n| Version | Status |\n|---|---|\n| CloudLinux 7 | Not vulnerable (filters interpreted, not compiled) |\n| CloudLinux 7h / 8 | Vulnerable; fix coming once AlmaLinux 8 releases it |\n| CloudLinux 8 LTS / 9 LTS (TuxCare ELS) | Vulnerable; follows the Red Hat release |\n| CloudLinux 9 / 10 | Vulnerable; follows the AlmaLinux kernel, Red Hat has not yet published the fix |\n| CloudLinux for Ubuntu 22.04 | Vulnerable; fix expected from Canonical, not yet released |\n| KernelCare livepatch | Follows vendor fixes, no advance patching |\n\nTo check whether a KernelCare server is patched, CloudLinux provides the command:\n\n\nkcarectl --patch-info | grep -E 'CVE-2026-6450[78]'\n\n\nnoting that kcarectl --info does not list CVEs and may make an unpatched server appear patched.\n\nThe upstream fix dates back to 25 July 2026 (two separate commits, one adding the hook in the BPF core and one enabling it on x86). Red Hat, AlmaLinux and Canonical have not yet released it. CloudLinux will update the advisory as each stream publishes the corrected kernel.\n

Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: CloudLinux – sicurezza e rilasci.