Full Report
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs
Analysis Summary
# Vulnerability: Spectre-v2 Branch Target Reuse (BTR)
## CVE Details
- CVE ID: CVE-2026-64507, CVE-2026-64508
- CVSS Score: Not specified in the article
- CWE: Not specified (Microarchitectural/Hardware Flaw)
## Affected Systems
- Products: Just-In-Time (JIT) engines across multiple CPU vendors (including Intel hardware). Specific software includes SpiderMonkey (Mozilla Firefox JIT engine), GraalVM, and the Linux kernel's cBPF JIT.
- Versions: Systems running vulnerable versions of the Linux kernel, SpiderMonkey, and GraalVM prior to the integration of BTR mitigations.
- Configurations: Systems running environments where unprivileged local code can be executed within a JIT engine.
## Vulnerability Description
Branch Target Reuse (BTR) is a new variant of the Spectre-v2 vulnerability that exploits the interplay between Self-Modifying Code (SMC) and indirect branch prediction within JIT engines.
While modern CPUs restore architectural code coherence after code modification, they do not immediately invalidate stale indirect branch prediction entries inside the Branch Target Buffer (BTB). In JIT environments, these stale entries can outlive the original freed code. When the code cache is later repopulated, this discrepancy creates a transient "execute-after-free" primitive. An attacker can use this to hijack transient control flow, redirecting it to newly generated code at obsolete offsets, allowing them to bypass software hardening protections and execute misaligned instructions to access sensitive data.
## Exploitation
- Status: PoC available
- Complexity: High
- Attack Vector: Local
## Impact
- Confidentiality: High (Enables disclosure of sensitive host/kernel data, including root password hashes)
- Integrity: None
- Availability: None
## Remediation
### Patches
- Mitigations for BTR have been developed and merged into the Linux kernel under identifiers CVE-2026-64507 and CVE-2026-64508. Users should update their Linux distributions and relevant JIT runtimes to the latest patched versions.
### Workarounds
- None specified in the article.
## Detection
- Specific indicators of compromise are not detailed in the article. Detection typically involves monitoring for unusual cache-timing side-channel analysis patterns or microarchitectural anomalies, though reliable software-based detection for transient execution attacks remains challenging.
## References
- hxxps://thehackernews[.]com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
- hxxps://www.vusec[.]net/projects/btr
- hxxps://spectreattack[.]com/
- hxxps://lore.kernel[.]org/linux-cve-announce/2026072554-CVE-2026-64507-5288@gregkh/