It's been a while since any new Spectre vulnerabilities have come to light but that's changing today. The embargo has now lifted on BTR, Branch Target Reuse as a new Spectre-V2 attack affecting just-in-time (JIT) compilers...

It's been a while since any new Spectre vulnerabilities have come to light but that's changing today. The embargo has now lifted on BTR, Branch Target Reuse as a new Spectre-V2 attack affecting just-in-time (JIT) compilers.
Security researchers at VUSec have announced today Branch Target Reuse as a Spectre-V2 attack in JIT engines affecting the Linux kernel with BPF, Oracle's GraalVM, and also the Mozilla SpiderMonkey JavaScript engine for Firefox.
BTR amounts to a speculative execute-after-free primitive with JIT compilers when not invalidating stale indirect branch prediction entries. One of the end-to-end exploits developed by VUSec is for leaking arbitrary memory on modern Intel CPUs in bypassing all enabled mitigations. All processors evaluated by the VUSec team were found to be impacted by Branch Target Reuse including Intel, AMD, and Arm hardware.
Hardware vendors are encouraging existing mitigation mechanisms. In July when this was privately disclosed, the Linux kernel landed patches to enabling Indirect Branch Predictor Barrier (IBPB) flush on BPF JIT allocations and support in the BPF kernel code for hardening against JIT spraying. Back in July I covered the kernel changes at the time in Linux 7.2-rc2 BPF Code Being Hardened Against JIT Spraying Attacks. Thus no new Linux kernel mitigations out today as the BPF changes have been mainlined since July and also back-ported already to stable kernel versions.
For Oracle GraalVM, randomizing JIT code-cache locations is being done to hinder BTR. Mozilla is said to have evaluated IBPB-based mitigations for SpiderMonkey but instead prioritizing work on site isolation capabilities.
Those wanting to learn more about BTR can do so at VUSec.net.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses | 0 | 9.23 | 29-09-2026 |
| 2 | Branch Target Reuse, nový útok typu Spectre v2 cílící na JIT kompilátory | 0 | 9.19 | 30-09-2026 |
| 3 | iTPROTECT выпустил новую версию iTPROTECT Scout | 0 | 8.01 | 28-09-2026 |
| 4 | iTProtect выпустил новую версию iTProtect Scout | 0 | 7.79 | 28-09-2026 |
| 5 | iTProtect выпустил новую версию iTProtect Scout | 0 | 7.79 | 28-09-2026 |
| 6 | Citrix Netscaler: Kritische Sicherheitslücken erlauben Codeeinschleusung | 0 | 9.03 | 27-09-2026 |
| 7 | AMD Posts GCC Compiler Patches For AVX10V1AUX ISA Support | 0 | 11.85 | 24-09-2026 |
| 8 | OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted | 0 | 8.31 | 30-09-2026 |
| 9 | Redox OS Adds IO_uring-Like API, NUMA & Gets QEMU Working | 0 | 14.93 | 25-09-2026 |
| 10 | Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд | 0 | 9 | 26-09-2026 |