Branch Target Reuse Spectre-v2 Variant Leaks Kernel Memory
VUSec disclosed Branch Target Reuse, a Spectre-v2 JIT attack that leaks Linux kernel memory, including root password hashes, despite default defenses.
On September 29, 2026, researchers at VUSec (VU Amsterdam) and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a Spectre-v2 variant that abuses stale branch-predictor entries left when self-modifying JIT code reuses freed code-cache memory, creating a transient execute-after-free primitive. End-to-end exploits against the Linux kernel's unprivileged cBPF JIT leak arbitrary memory at 8 bytes per second and recover the root password hash from a running su process in 3–5 minutes on fully updated Intel Raptor Cove and Lion Cove systems with default mitigations; a variant also bypassed constant blinding and still recovered the hash within five minutes. No current Intel, AMD, or Arm CPU is reported to keep the branch predictor synchronized with modified code, and affected software includes the Linux cBPF JIT, SpiderMonkey (Firefox), and GraalVM. Linux merged fixes tied by two outlets to CVE-2026-64507 and CVE-2026-64508, including an x86 IBPB when cBPF reuses previously used memory; Oracle partially mitigated GraalVM with code-cache randomization, Mozilla is prioritizing site isolation, and AMD says existing Spectre-v2 guidance applies. A September 30 oss-security note adds a CCS 2026 paper, project page, and public GitHub and references mitigations, but unlike The Hacker News and BleepingComputer it does not name those CVEs or report exploitation in the wild.
- On 2026-09-29, VUSec (VU Amsterdam) and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a Spectre-v2 variant that reuses stale branch-predictor/BTB entries after JIT code-cache reuse, yielding a transient execute-after-free…
- End-to-end exploits against Linux's unprivileged cBPF JIT leak memory at 8 bytes per second and recover the root password hash from a running su process in 3–5 minutes on fully patched Intel Raptor Cove and Lion Cove CPUs with default…
- A variant bypassed constant-blinding hardening and still recovered the hash within five minutes.
- The behavior was confirmed on Intel, AMD, and Arm; sources say no current CPU keeps the branch predictor in sync with modified code. Affected targets also include SpiderMonkey (Firefox) and GraalVM.
- The Hacker News and BleepingComputer cite CVE-2026-64507 and CVE-2026-64508, with Linux fixes already merged, including an x86 IBPB when cBPF reuses previously used memory.
- Oracle partially mitigated GraalVM via code-cache randomization; Mozilla is prioritizing site isolation; AMD says existing Spectre-v2 guidance applies.
- A 2026-09-30 oss-security note points to a CCS 2026 paper, project page, and public GitHub and mentions mitigations, but names no CVE and reports no in-the-wild exploitation.
Coverage timelineoldest first · each row is one article
- · 13h agoNew Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
The Hacker News· 72
BTR, a new Spectre-v2 variant from VUSec researchers, hijacks stale JIT branch predictions to leak kernel secrets from fully patched systems.
- · 13h agoNew Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
SecurityWeek· 70
New Spectre-v2 variant BTR lets attackers leak arbitrary memory, including root password hashes, from Intel, AMD, and Arm systems via stale JIT branch predictions.
- · 13h agoNew Spectre v2 attack variant leaks Linux root password hash in minutes
BleepingComputer· 63
Vulnerabilities in this storyAll →
- CVE-2026-64507—<1%Linux kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2…published · Linux kernel+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-64507+1 related CVE | Linux kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2… In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence. This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n. |