Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Experts Question the White House’s Defense of Taxpayer-Funded Ads

    September 29, 2026

    Mystery over UK airbase scare as police find ‘quantity of petrol’ but no explosives

    September 29, 2026

    More than 400 detained as France student protests escalate

    September 29, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Experts Question the White House’s Defense of Taxpayer-Funded Ads
    • Mystery over UK airbase scare as police find ‘quantity of petrol’ but no explosives
    • More than 400 detained as France student protests escalate
    • Conference laps up Andy unplugged as he offers chance to take road less travelled | John Crace
    • Anthropic Says It Discovered a Crispr-Like System. Now What?
    • Liquid AI Releases d1: A Decision Model That Returns Calibrated Probabilities With Zero Output Tokens
    • New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
    • Bitcoin drops to $82,000 on US data, and inflation fear is blamed
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 29, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 29, 2026Vulnerability / Hardware Security

    A group of academics from VUSec and Scuola Superiore Sant’Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.

    The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR).

    “The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets),” researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida said in an accompanying paper.

    “In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a transient execute-after-free primitive. This allows attackers to hijack transient control flow to newly generated code at obsolete offsets, bypassing software hardening or reaching misaligned gadgets.”

    BTR was evaluated against SpiderMonkey (the JIT engine of Mozilla Firefox), GraalVM, and the Linux kernel’s cBPF JIT, all of which have been found to be affected, although with “markedly different exploitability characteristics and leakage rates.”

    As a proof-of-concept, two end-to-end exploits have been devised against the Linux kernel that can be used to leak and recover the root password hash within minutes from a fully patched Intel system with default protections enabled.

    Cybersecurity

    Spectre refers to a class of CPU security vulnerabilities first discovered in 2017 that exploit speculative execution, a performance optimization technique that modern processors use to predict and execute instructions beforehand.

    An attacker can exploit this loophole to trick a CPU into performing speculative operations that access sensitive data, and then infer that data through a cache timing side channel.

    Spectre v2 is one specific type of the Spectre attack that abuses indirect branch prediction in modern processors to achieve the same goals. Specifically, it poisons the CPU’s branch prediction mechanism to cause a victim program to execute an indirect branch, which, in turn, causes the CPU to mispredict the branch and speculatively execute attacker-controlled code or a gadget.

    Although the results of the misprediction are discarded, an attacker can infer what the victim’s speculative execution accessed by taking advantage of the cache state changes and measuring the cache changes.

    “BTR targets JIT engines and arises from the interplay between Self-Modifying Code (SMC) and indirect branch prediction,” the researchers said, adding, “JIT engines do expose exploitable transient-execution opportunities induced by SMC for the first time.”

    The attack presumes an attacker who is able to run unprivileged code in a JIT engine and is seeking to disclose sensitive data from the host environment. The entire sequence of actions is as follows –

    • The attacker lures the JIT engine into allocating a training chunk and forces the victim branch to jump to it, thereby inserting a BTB entry referencing the current entry point.
    • The attacker forces a deallocation of the training chunk and an allocation of the target chunk that partially reuses the same address.
    • The attacker triggers the indirect branch again, the CPU uses the now-stale branch target buffer (BTB) entry and speculatively jumps to the old training-chunk entry point.
    • The end result is control-flow hijacking and secret data disclosure.

    “By redirecting control flow to an architecturally invalid entry point, the attacker can bypass Spectre hardening mitigations or execute misaligned instructions, ultimately disclosing secret data,” the researchers explained.

    Cybersecurity

    However, a key aspect BTR hinges on is that the stale BTB entry must not be invalidated or replaced after the JIT engine frees the training chunk, and the branch predictor must select the stale BTB entry for prediction.

    Following responsible disclosure, mitigations for BTR have been released and merged into the Linux kernel (CVE-2026-64507 and CVE-2026-64508).

    “GraalVM instead hinders region reuse by randomizing JIT code-cache locations,” the researchers said. “Mozilla considered IBPB [Indirect Branch Predictor Barrier]-based mitigations, but is currently prioritizing the completion and deployment of site isolation.”

    The disclosure comes nearly two months after MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed a speculative execution attack technique called Interrupt Injection that can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel- and AMD-based Linux systems.

    attack BTR defenses Existing leaks Linux memory Spectrev2
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

    FBI tells ShinyHunters members to turn themselves in after recent arrest

    New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

    Former US Air Force members sent to prison over BEC attacks

    DARPA Selects Xint to Use AI in Securing Military Messaging Apps

    Automated AI agent used to breach cybersecurity nonprofit DIVD

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Experts Question the White House’s Defense of Taxpayer-Funded Ads

    September 29, 2026

    Mystery over UK airbase scare as police find ‘quantity of petrol’ but no explosives

    September 29, 2026

    More than 400 detained as France student protests escalate

    September 29, 2026

    Conference laps up Andy unplugged as he offers chance to take road less travelled | John Crace

    September 29, 2026
    Latest Posts

    Bitcoin collateral: MARA’s $600M Long Ridge financing

    August 7, 2026

    Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix

    August 7, 2026

    The best classic slasher movie you’ll never watch

    August 7, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Experts Question the White House’s Defense of Taxpayer-Funded Ads

    September 29, 2026

    Mystery over UK airbase scare as police find ‘quantity of petrol’ but no explosives

    September 29, 2026

    More than 400 detained as France student protests escalate

    September 29, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.