CVE-2026-64508
EPSS 0.2% (10º percentile). Patch Microsoft: CBL-Mariner Releases.
Vulnerabilità · 8 ore fa
VUSec e Scuola Superiore Sant'Anna hanno presentato BTR, una nuova variante di Spectre-v2 che colpisce i JIT di kernel, browser e runtime. Nei test su Linux, su sistemi Intel completamente patchati, ha permesso di recuperare l'hash della password di root in pochi minuti.
Il punto debole è la fiducia residua nei branch target vecchi. La CPU conserva previsioni indirette ormai stale, e i JIT possono riutilizzare la stessa memoria quando rigenerano il codice: l'esecuzione speculativa viene così deviata verso un punto sbagliato del nuovo codice e lascia filtrare dati dalla memoria.
Per chi mantiene kernel, browser o runtime, il messaggio è che “Spectre-v2 mitigato” non equivale automaticamente a “leak chiuso” nei percorsi che riscrivono codice al volo. Il problema tocca più stack e più vendor, non una singola applicazione.
EPSS 0.2% (10º percentile). Patch Microsoft: CBL-Mariner Releases.
EPSS 0.2% (5º percentile). Patch Microsoft: CBL-Mariner Releases.
3 fonti che coprono questa storia
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
Spectre BTR reuses stale JIT branch targets; Linux PoCs recover the root password hash within minutes on a fully patched Intel system.
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
Part of the PlainSec briefing for 2026-09-29