BTR Reuses Stale JIT Predictions for Spectre Leaks
Academic researchers from VUSec and Scuola Superiore Sant’Anna published Branch Target Reuse (BTR), a new Spectre-v2 variant that affects JIT engines in Linux, Mozilla Firefox’s SpiderMonkey, and Oracle’s GraalVM. On fully patched Intel systems, the Linux proof-of-concept can recover the root password hash in minutes.
BTR works because CPUs may keep stale indirect branch targets after code changes. When a JIT engine later repopulates that memory, the processor can be nudged into following an old prediction into new code at the wrong offset, creating a transient leak path and bypassing Spectre-v2 defenses that assume repopulated code is safe.
For kernel, browser, and runtime teams, the important map is the JIT cache, not a single application bug. If your software rewrites code at runtime, “Spectre-v2 mitigated” does not necessarily mean speculative leaks are closed, and on Linux the cBPF path gives even unprivileged filtering features a route to kernel-memory disclosure.
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.