The published attack doesn’t work on the CloudLinux 7h and 8 kernels, according to our analysis of their code, so no update is needed for these versions. Red Hat lists RHEL 8 as affected by CVE-2026-64507 and not affected by CVE-2026-64508. If Red Hat releases a fix for RHEL 8, CloudLinux 7h and 8 will pick it up once AlmaLinux 8 has it, and we’ll note it here.
Posted Oct 07, 2026 - 12:34 UTC
Identified
BTR (CVE-2026-64507, CVE-2026-64508, Moderate per Red Hat) is a Spectre v2 variant that lets a local unprivileged user read kernel memory. It does not give root by itself. A public proof-of-concept exists for two Intel processor microarchitectures, and no exploitation in the wild has been reported.
Processors: whether an attack can succeed also depends on the processor. The published exploit works on two Intel microarchitectures only. → Which processors are at risk
Fix status: fixed upstream on July 25, 2026. Red Hat, AlmaLinux and Canonical haven’t released it yet. → Update instructions CloudLinux 7h and 8 kernel: CloudLinux builds it once AlmaLinux 8 has the fix. AlmaLinux kernel (CloudLinux 9, 10): follows Red Hat, which lists its kernels as affected and has released no fix yet. LTS kernels (CloudLinux 8 LTS, 9 LTS): follow Red Hat’s release. KernelCare livepatch: follows the vendor fixes. CloudLinux for Ubuntu 22.04: the fix comes from Canonical, which hasn’t released it for 22.04 yet.