New Spectre BTR Attack Exposes Linux Memory
Researchers have identified a new Spectre-based vulnerability called Branch Target Reuse (BTR) that affects Linux memory. The exploit targets JIT compilation processes, allowing attackers to potentially recover sensitive data like root password hashes.
Why it matters
This discovery highlights a persistent security flaw in speculative execution, suggesting that current hardware protections may be insufficient against evolving side-channel attacks.
Researchers have uncovered a new Spectre variant that exploits the way processors remember the locations of dynamically generated code, demonstrating that sensitive Linux memory can be exposed even when existing speculative-execution protections are enabled.
The technique, called Branch Target Reuse (BTR) , targets just-in-time compilation, the process used by browsers, language runtimes and parts of the Linux kernel to turn code into machine instructions while software is running. Its central finding is that replacing executable code does not necessarily erase the processor’s predictions about where that code used to begin.
The research team at VUSec and Scuola Superiore Sant’Anna investigated Linux’s classic Berkeley Packet Filter, Firefox’s SpiderMonkey engine and Oracle’s GraalVM. Their strongest practical result was against Linux, where they developed two end-to-end exploits and demonstrated recovery of a root password hash.
Also covering this story
One other newsroom covered this event. We read that version too.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in