
New Spectre-v2 BTR Attack Leaks Linux Kernel Memory Despite Existing Defenses
Academics from VUSec and Scuola Superiore Sant'Anna have disclosed Branch Target Reuse (BTR), a new Spectre v2 variant. It bypasses existing defenses and can recover a root password hash from a patched Intel Linux system within minutes.
Academics from VUSec and Scuola Superiore Sant'Anna have disclosed a new Spectre v2 variant that affects the Just-In-Time (JIT) engines used by web browsers, language runtimes and the Linux kernel across multiple CPU vendors. The attack has been codenamed Branch Target Reuse (BTR).
In an accompanying paper, researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi and Cristiano Giuffrida write that modern CPUs restore architectural code coherence after self-modification but do not necessarily invalidate stale indirect branch prediction entries. In JIT engines those stale targets can outlive the original code and be reused once the code cache is repopulated, producing a transient execute-after-free primitive. Attackers can then hijack transient control flow into newly generated code at obsolete offsets, bypassing software hardening or reaching misaligned gadgets.
What was tested
BTR was evaluated against SpiderMonkey, the JIT engine of Mozilla Firefox, against GraalVM and against the Linux kernel's cBPF JIT. All three were found to be affected, though with markedly different exploitability characteristics and leakage rates. The attack assumes an adversary who can already run unprivileged code inside a JIT engine and wants to disclose sensitive data from the host environment.
Root password hash in minutes
As a proof of concept the team devised two end-to-end exploits against the Linux kernel. According to the researchers, these can leak and recover the root password hash within minutes from a fully patched Intel system with default protections enabled.
Fixes and vendor responses
Mitigations for BTR have been released and merged into the Linux kernel as CVE-2026-64507 and CVE-2026-64508. GraalVM blocks region reuse by randomizing JIT code-cache locations. Mozilla considered IBPB (Indirect Branch Predictor Barrier) based mitigations but is currently prioritizing the completion and deployment of site isolation.
The disclosure comes nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan described Interrupt Injection, a speculative execution technique that can also bypass Spectre v2 defenses and leak kernel memory from Intel- and AMD-based Linux systems.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.