CVE-2026-64508
EPSS 0.2% (10th percentile). Microsoft patch: CBL-Mariner Releases.
Vulnerabilities · 8h ago
Academic researchers from VUSec and Scuola Superiore Sant’Anna published Branch Target Reuse (BTR), a new Spectre-v2 variant that affects JIT engines in Linux, Mozilla Firefox’s SpiderMonkey, and Oracle’s GraalVM. On fully patched Intel systems, the Linux proof-of-concept can recover the root password hash in minutes.
BTR works because CPUs may keep stale indirect branch targets after code changes. When a JIT engine later repopulates that memory, the processor can be nudged into following an old prediction into new code at the wrong offset, creating a transient leak path and bypassing Spectre-v2 defenses that assume repopulated code is safe.
For kernel, browser, and runtime teams, the important map is the JIT cache, not a single application bug. If your software rewrites code at runtime, “Spectre-v2 mitigated” does not necessarily mean speculative leaks are closed, and on Linux the cBPF path gives even unprivileged filtering features a route to kernel-memory disclosure.
EPSS 0.2% (10th percentile). Microsoft patch: CBL-Mariner Releases.
EPSS 0.2% (5th percentile). Microsoft patch: CBL-Mariner Releases.
3 sources covering this story
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
Spectre BTR reuses stale JIT branch targets; Linux PoCs recover the root password hash within minutes on a fully patched Intel system.
New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel
New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average.
Part of the PlainSec briefing for 2026-09-29