Spectre bug is back, this time to haunt JIT engines
Researchers disclose Branch Target Reuse, a Spectre v2 JIT attack that can leak Linux root password hashes.
Researchers from Vrije Universiteit and Scuola Superiore Sant'Anna describe Branch Target Reuse, an in-place Spectre v2 attack against JIT engines that reuses stale indirect branch-prediction entries after code-cache reuse. They demonstrated proofs of concept on an Intel Linux kernel that leak the root password hash despite cBPF constant binding, at about 5.7 KB/s on Raptor Cove and 5.4 KB/s on Lion Cove. Affected engines include Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey. Linux and Oracle deployed mitigations and CVE-2026-64507 and CVE-2026-64508 were assigned; Mozilla is prioritizing site isolation instead of a direct fix. The paper was accepted to ACM CCS 2026.
- Branch Target Reuse reuses stale indirect-branch predictions in JIT code caches.
- Linux cBPF proofs of concept leaked root password hashes at about 5.5 KB/s.
- Engines named include Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey.
- Linux and Oracle mitigated the issue; Mozilla is prioritizing site isolation.
- CVE-2026-64507 and CVE-2026-64508 were assigned; the paper is at CCS 2026.
Vulnerabilities mentionedAll →
- CVE-2026-64507—<1%Linux kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2…published · Linux kernel+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-64507+1 related CVE | Linux kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2… In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence. This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n. |
Full article524 words · extracted from theregister.com · click to collapse
security
Researchers find a way to recover stale indirect branch prediction entries
The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, runtimes, and kernels.
The vulnerability is found in many CPUs that use speculative execution, the process of executing code before it is called to boost performance. Researchers found speculative execution opens the door to side channel attacks through which secrets can be exposed or inferred.
When news of that risk became known, chipmakers and OS developers scrambled to fix these vulnerabilities, which were referred to as Spectre and Meltdown. And since then, researchers have found two or three dozen variations, such as 2025's VMScape, one of several so-called "Spectre v2" attacks that attempt to exploit indirect branch prediction, where program control is passed indirectly by pointing to an address where the next instruction can be found rather than specifying the instruction itself.
REG AD
The attacker trains the branch predictor to execute speculatively to a chosen address in order to leak data about the microarchitecture state.
REG AD
Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have revived Spectre in a form called Branch Target Reuse (BTR), which they describe as the first practical in-place Spectre v2 attack that attacks just-in-time (JIT) compilers. An in-place attack is confined to the victim's branch while an out-of-place attack relies on speculation directed toward a target on a different branch.
The researchers – Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida – found that this novel Spectre form can be conjured from code left in JIT engines including Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey.
"The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," the authors explain. "In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a speculative execute-after-free primitive."
The result is that an attacker can commandeer speculative control flow in a way that avoids some software defenses like FineIBT [PDF]. The authors showed they could exploit this flaw by designing two proof-of-concept exploits against an Intel-based Linux kernel that reveal the root password hash even with the constant binding defense provided by cBPF.
The expected leakage rate is 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove. It's slow but enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system.
After the researchers disclosed their findings, Linux kernel developers and Oracle put mitigations in place. Two CVEs were assigned: CVE-2026-64507 and CVE-2026-64508. Mozilla, the researchers said, has opted to prioritize work on site isolation instead of addressing the issue directly. Strong mitigations like IBPB are said to be effective but add complexity and hinder performance.
The Branch Target Reuse paper has been accepted for publication at the ACM Conference on Computer and Communications Security (CCS) 2026, which will be held November 15 through 19 in The Hague, Netherlands. ®