Researchers at VU Amsterdam’s VUSec group and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse (BTR), a Spectre v2 variant that targets just-in-time compilers rather than the usual indirect-call paths. In the Linux kernel demonstration, an unprivileged local attacker recovers a root password hash from a running su process in roughly three to five minutes on Intel Raptor Cove and Lion Cove cores. The paper (Sander Wiebing, Yuhui Zhu, Alessandro Biondi, Cristiano Giuffrida) has been accepted to ACM CCS 2026.
What happened
BTR exploits a gap between self-modifying code and the CPU’s indirect branch predictor. Modern CPUs keep architectural code coherent when memory is rewritten, but they do not necessarily invalidate stale indirect-branch prediction entries pointing at the old code. When a JIT frees a code region and later emits new code over the same addresses, the predictor can still remember a target from the old, attacker-influenced code.
The attacker’s sequence:
- Train a victim indirect branch to jump into a chunk of JIT code the attacker controls.
- Get that chunk deallocated.
- Arrange for newly emitted JIT code to overlap part of the same addresses.
- Trigger the branch again. The CPU speculatively executes at the stale target, an effectively “transient execute-after-free” primitive.
- Read the secret back through the cache, byte by byte, as in classic Spectre.
Technical details
Three JIT targets were evaluated and all were found affected:
- Linux kernel cBPF JIT: the headline result. The proof of concept leaks kernel memory at about eight bytes per second, enough to pull a root hash from an
suprocess within minutes. Tracked as CVE-2026-64507 and CVE-2026-64508. - Mozilla SpiderMonkey (Firefox): stale predictions survive across JIT code reuse.
- Oracle GraalVM: the researchers found a way past a sandbox check.
The kernel demo runs on Intel, but the VUSec project page lists AMD and Arm processors as affected as well, because the weakness lies in how indirect branch prediction works generally rather than in one vendor’s design. It also defeats existing Spectre v2 defenses in the configurations tested, which is what makes it notable: the attack does not rely on cross-domain training that current isolation mitigations target.
Impact
Exploitation requires local code execution and the ability to load classic BPF programs (for example via seccomp filters or socket filters), so this is not a remote attack. The exposure is concentrated in:
- Multi-tenant Linux hosts and shared build runners where untrusted users run code.
- Container hosts, where a container workload can load cBPF filters. Kernel memory leakage crosses the container boundary.
- Workstations and servers that also run browsers or GraalVM-based services.
Leaked secrets are not limited to password hashes; anything resident in kernel-accessible memory (keys, tokens, credentials of other processes) is a potential target, subject to attacker ability to steer the gadget.
Mitigation
- Linux kernel: fixes are merged upstream. They issue an IBPB (indirect branch predictor barrier) when BPF JIT code is allocated in memory previously used for executed BPF code, plus hardening against BPF JIT spraying. Update to a kernel release or distribution backport containing the CVE-2026-64507 / CVE-2026-64508 fixes and reboot.
- GraalVM: mitigated by randomizing JIT code-cache locations and hindering region reuse. Apply the vendor update.
- Firefox/SpiderMonkey: Mozilla has considered IBPB-based mitigations but is currently prioritizing completion and deployment of site isolation.
- Defense in depth: restrict unprivileged BPF where possible (
kernel.unprivileged_bpf_disabled=1), keepbpf_jit_hardenenabled, tighten seccomp policy in multi-tenant workloads, and do not co-locate untrusted tenants with sensitive workloads on the same cores. - Expect microcode and firmware guidance from Intel, AMD and Arm; track vendor advisories and distro security trackers.
There is no evidence of in-the-wild exploitation. Treat this as a patch-in-normal-cycle issue for most fleets, and prioritize multi-tenant, CI runner and container-host kernels.