Security advisory #18

Information

State: published
Published at: 2026-08-09 22:25:58 CEST
CVEs: CVE-2026-64507
Name: x86 BPF JIT predictor reuse
Summary: English: Kernel information disclosure
Česky: Únik informací z jádra
Description: English: An ordinary VPS process can use classic BPF programs to influence branch predictions left behind when executable JIT memory is reused. On affected x86 processors this is a speculative-information-disclosure building block. It may help an exploit obtain secrets needed for root inside a VPS, but it is not a complete privilege-escalation exploit. The reviewed technical evidence does not establish which secrets can be recovered in the deployed configuration or a complete path to root on the node or disclosure from another VPS. A loss of node availability is not expected.
Česky: Běžný proces ve VPS může pomocí klasických programů BPF ovlivnit predikce větvení, které zůstaly po opětovném použití spustitelné paměti JIT. Na dotčených procesorech x86 jde o stavební prvek pro spekulativní únik informací. Může zneužití pomoci získat tajné údaje potřebné pro root uvnitř VPS, ale nejde o úplný způsob eskalace oprávnění. Analyzované technické podklady nepopisují, která tajná data lze v nasazeném prostředí získat, ani úplný postup k získání root na node nebo dat z jiného VPS. Ztráta dostupnosti node se neočekává.
Response: English: The predictor-flushing fix is included starting with vpsAdminOS kernel live patch 6.12.95.2. Upstream Linux includes the architecture support in 6.12.97 and later stable releases; CVE-2026-64508 supplies the matching allocator hook.
Česky: Oprava čištění prediktoru je součástí vpsAdminOS kernel live patche od verze 6.12.95.2. Ve stabilních vydáních Linuxu je podpora architektury obsažena od verze 6.12.97; CVE-2026-64508 doplňuje odpovídající volání v alokátoru.

Node status

Node State Vulnerable until Mitigated since Note
node19.prg mitigated 2026-08-06 04:45:59 CEST 2026-08-06 04:46:29 CEST
node20.prg mitigated 2026-08-06 04:46:05 CEST 2026-08-06 04:46:36 CEST
node21.prg mitigated 2026-08-06 04:46:08 CEST 2026-08-06 04:46:38 CEST
node22.prg mitigated 2026-08-06 04:45:54 CEST 2026-08-06 04:46:24 CEST
node23.prg mitigated 2026-08-06 04:46:04 CEST 2026-08-06 04:46:34 CEST
node24.prg mitigated 2026-08-06 04:46:25 CEST 2026-08-06 04:46:55 CEST
node25.prg mitigated 2026-08-06 04:46:16 CEST 2026-08-06 04:46:46 CEST
backuper2.prg not affected - -
node5.brq mitigated 2026-08-09 05:05:47 CEST 2026-08-09 05:06:17 CEST
node6.brq mitigated 2026-08-06 04:46:23 CEST 2026-08-06 04:46:53 CEST
node1.pgnd mitigated 2026-08-06 04:24:40 CEST 2026-08-06 04:25:10 CEST
node1.stg mitigated 2026-08-06 03:30:50 CEST 2026-08-06 03:31:39 CEST
node2.stg mitigated 2026-08-06 03:29:49 CEST 2026-08-06 03:30:14 CEST

Updates

Date Summary Reported by
No updates posted.

Security advisories


vpsFree.cz support

Support mail: support@vpsfree.org

Links

Status
https://status.vpsf.cz

IRC
irc.libera.chat #vpsfree

Matrix
#vpsfree:matrix.org

Discourse
https://discourse.vpsfree.cz

Knowledge base
https://kb.vpsfree.org/

Sysadmins contacts

Jakub Skokan
IRC: aither at #vpsfree
Phone: +420 775 386 453

Pavel Snajdr (main admin)
IRC: snajpa at #vpsfree
Phone: +420 720 107 791