Skip to main content
CybersecurityVulnerability Management

New Spectre Variant BTR Exploits Linux Memory Despite Existing Defenses

Computer chip on laboratory bench surrounded by scientific instruments.

"JIT engines do expose exploitable transient-execution opportunities induced by SMC for the first time," researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida wrote in their paper disclosing the new Spectre-v2 variant codenamed Branch Target Reuse (BTR). The vulnerability reopens a speculative‑execution pathway that defenses implemented since 2017 do not fully block, and it affects multiple JIT engines and the Linux kernel.

How Branch Target Reuse (BTR) works

BTR exploits the interaction of self‑modifying code (SMC) in JIT engines and stale entries in the CPU's indirect branch prediction structures, specifically the Branch Target Buffer (BTB). The researchers describe a four‑step sequence an attacker can use:

  • lure the JIT into allocating a training chunk and force a victim indirect branch to jump to it, creating a BTB entry;
  • force deallocation of the training chunk and allocate a target chunk that partially reuses the same address;
  • trigger the indirect branch again so the CPU consults the stale BTB entry and speculatively jumps to the old training‑chunk entry point;
  • use the resulting transient control‑flow hijack to bypass hardening or execute misaligned instructions and leak secrets via cache side channels.

The researchers explain that modern CPUs restore "architectural code coherence after self‑modification" but do not necessarily invalidate stale indirect branch prediction entries, allowing the stale targets to be reused when code caches are repopulated.

Affected runtimes and exploitability differences

The authors evaluated BTR against three real targets and found differing characteristics and leakage rates. The affected software named in the disclosure includes:

  • SpiderMonkey, Mozilla's JIT engine used in Firefox;
  • GraalVM;
  • the Linux kernel's cBPF JIT.

According to the paper, all three are affected but with "markedly different exploitability characteristics and leakage rates." GraalVM mitigates region reuse by randomizing JIT code‑cache locations. Mozilla considered Indirect Branch Predictor Barrier (IBPB)‑based mitigations but is "currently prioritizing the completion and deployment of site isolation," the researchers said.

Proof‑of‑concept kernel exploits and real‑world impact

The academics produced two end‑to‑end proof‑of‑concept exploits that target the Linux kernel. In those demos, an attacker running unprivileged code in a JIT environment can leak and recover the root password hash "within minutes" on a fully patched Intel system with default protections enabled. The disclosure stresses that BTR presumes an attacker able to run unprivileged JIT code and who is seeking to disclose sensitive host data.

Because the technique relies on stale BTB entries that are not invalidated or replaced, the attack's success depends on the branch predictor selecting the stale target at the time of the indirect branch. When that happens, redirecting control flow to an "architecturally invalid entry point" can bypass existing Spectre mitigations or enable execution of misaligned instruction sequences that expose secrets via cache timing channels.

Mitigations merged into Linux and vendor responses

Following responsible disclosure, the researchers reported that mitigations for BTR have been released and merged into the Linux kernel under CVE‑2026‑64507 and CVE‑2026‑64508. The paper also records vendor‑level approaches: GraalVM's countermeasure randomizes JIT code‑cache locations to hinder region reuse, and Mozilla weighed IBPB‑based defenses but is prioritizing site isolation.

How Mozilla, GraalVM, and Linux operators should respond

Mozilla: the disclosure notes Mozilla considered IBPB‑based mitigations but is "currently prioritizing the completion and deployment of site isolation." That signals a preference for a defensive approach based on process and memory separation rather than immediate IBPB use, according to the researchers' account.

GraalVM: the runtime "hinders region reuse by randomizing JIT code‑cache locations," a design choice the researchers identify as reducing the attack surface for BTR.

Linux operators and kernel maintainers: the Linux kernel already received merged mitigations (CVE‑2026‑64507 and CVE‑2026‑64508). Operators should track those kernel updates and apply them to systems where JIT‑capable unprivileged code may run alongside privileged kernel memory.

The BTR disclosure arrives nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan published Interrupt Injection, a speculative‑execution technique that the source says can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel‑ and AMD‑based Linux systems. Together, these disclosures show researchers continuing to discover speculative‑execution pathways that elude earlier mitigations.

For defenders, the practical picture is unvarnished: researchers have demonstrated that speculative control‑flow hijacks tied to JIT code cache reuse remain exploitable in deployed systems, and kernel patches plus runtime hardening are the immediate levers available. For attackers, the requirement remains the same — the ability to run unprivileged JIT code — but the potential prize, in the right environment, can be as tangible as a root password hash recovered in minutes.

Original story