In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because a certain preempting store operation does not necessarily occur before a store operation that has an attacker-controlled value.
https://www.openwall.com/lists/oss-security/2021/08/01/3
https://lists.debian.org/debian-lts-announce/2021/10/msg00010.html