New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

Researchers have identified a new Spectre-v2 vulnerability called Branch Target Reuse (BTR) that affects JIT engines in browsers and kernels. This flaw allows attackers to bypass software hardening and leak sensitive data, such as root password hashes, by exploiting stale branch prediction entries.
Why it matters
This vulnerability highlights persistent security risks in modern CPU speculative execution, potentially impacting millions of devices across multiple vendors.
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time ( JIT ) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors.
The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR) .
"The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida said in an accompanying paper.
"In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a transient execute-after-free primitive. This allows attackers to hijack transient control flow to newly generated code at obsolete offsets, bypassing software hardening or reaching misaligned gadgets."
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in