eBPF has a verifier to ensure that (Apart from other things) programs don't access memory they aren't supposed to.
Worth noting though that one of the Spectre PoCs actually used eBPF in order to access kernel memory! Though of course, of the CPU were working correctly, this wouldn’t be a big deal.