[PATCH 6.16.y 0/6] cBPF JIT spray hardening

Pawan Gupta pawan.kumar.gupta at linux.intel.com
Wed Jul 22 08:18:03 PDT 2026


On Tue, Jul 21, 2026 at 03:08:11PM +0200, Greg Kroah-Hartman wrote:
> On Tue, Jul 14, 2026 at 11:58:24AM -0700, Pawan Gupta wrote:
> > Hi,
> > 
> > These backports harden BPF JIT against spectre-v2 class of attacks. Without
> > a predictor flush, execution of new BPF program may use stale prediction
> > left behind by the freed one.
> > 
> > To avoid this, issue an IBPB flush on all CPUs on JIT program allocation.
> > The flush is conditional to spectre-v2 mitigation applied.
> > 
> > Patch 1-2: Adds the predictor flush hook and enables it on x86 via IBPB.
> > 
> > 	  bpf: Support for hardening against JIT spraying
> > 	  x86/bugs: Enable IBPB flush on BPF JIT allocation
> > 
> > Patch 3-6: Narrow the flush to only unprivileged JIT allocations
> > 	   to avoid redundant flushes. Also adds pack-selection changes
> > 	   that minimizes flushes.
> > 
> > 	  bpf: Restrict JIT predictor flush to cBPF
> > 	  bpf: Skip redundant IBPB in pack allocator
> > 	  bpf: Prefer packs that won't trigger an IBPB flush on allocation
> > 	  bpf: Prefer dirty packs for eBPF allocations
> > 
> > This one is mostly similar to 6.18:
> > 
> >   https://lore.kernel.org/all/20260713-cbpf-jit-spray-hardening-6-18-y-v1-0-755f60c55705@linux.intel.com/
> 
> There is no active 6.16.y kernel branch, so why is this being sent to
> us?

Sorry that was a mistake. I had an old 6.16.y worktree in my machine and I
assumed it was still active. Please ignore.



More information about the linux-riscv mailing list