BTR (CVE-2026-64507, CVE-2026-64508) Spectre v2 kernel memory leak

Incident Report for CloudLinux

Update

The published attack doesn’t work on the CloudLinux 7h and 8 kernels, according to our analysis of their code, so no update is needed for these versions. Red Hat lists RHEL 8 as affected by CVE-2026-64507 and not affected by CVE-2026-64508. If Red Hat releases a fix for RHEL 8, CloudLinux 7h and 8 will pick it up once AlmaLinux 8 has it, and we’ll note it here.
Posted Oct 07, 2026 - 12:34 UTC

Identified

BTR (CVE-2026-64507, CVE-2026-64508, Moderate per Red Hat) is a Spectre v2 variant that lets a local unprivileged user read kernel memory. It does not give root by itself. A public proof-of-concept exists for two Intel processor microarchitectures, and no exploitation in the wild has been reported.

Affected: every CloudLinux version except CloudLinux 7. → Affected CloudLinux versions

Processors: whether an attack can succeed also depends on the processor. The published exploit works on two Intel microarchitectures only. → Which processors are at risk

Mitigation: none. → Is there a mitigation?

Fix status: fixed upstream on July 25, 2026. Red Hat, AlmaLinux and Canonical haven’t released it yet. → Update instructions
CloudLinux 7h and 8 kernel: CloudLinux builds it once AlmaLinux 8 has the fix.
AlmaLinux kernel (CloudLinux 9, 10): follows Red Hat, which lists its kernels as affected and has released no fix yet.
LTS kernels (CloudLinux 8 LTS, 9 LTS): follow Red Hat’s release.
KernelCare livepatch: follows the vendor fixes.
CloudLinux for Ubuntu 22.04: the fix comes from Canonical, which hasn’t released it for 22.04 yet.

Why it matters: on a shared host, a compromised site is enough to run the attack. → Why this matters on a shared host

How the bug works: the processor keeps old branch predictions when the kernel reuses memory for a new filter program. → Technical details of the bug
Posted Oct 05, 2026 - 16:10 UTC