Full Report
Researchers find a way to recover stale indirect branch prediction entries
Analysis Summary
# Vulnerability: Branch Target Reuse (BTR) - Speculative Execute-After-Free
## CVE Details
- **CVE ID:** CVE-2026-64507, CVE-2026-64508
- **CVSS Score:** Not explicitly listed in the text (Estimated High; typically 7.0 - 8.8 for local side-channel leaks)
- **CWE:** CWE-1259 (Improper Restriction of Speculative Execution), CWE-416 (Use After Free - Speculative variant)
## Affected Systems
- **Products:**
- CPUs: Intel Raptor Cove and Lion Cove architectures (and potentially others using speculative execution).
- Software: Linux Kernel (cBPF), Oracle GraalVM, Mozilla SpiderMonkey JIT engine.
- **Versions:** Specific versions prior to July 2026/September 2026 updates.
- **Configurations:** Systems utilizing Just-In-Time (JIT) compilation where code cache is frequently repopulated or modified.
## Vulnerability Description
Branch Target Reuse (BTR) is a practical "in-place" Spectre v2 attack. It exploits a gap in microarchitectural coherence: while modern CPUs ensure architectural code coherence after self-modification (updating the actual instructions), they fail to invalidate **stale indirect branch prediction entries** in the Branch Target Buffer (BTB).
In JIT environments, when code is modified or freed, these stale branch targets persist. When the code cache is repopulated, the CPU may speculatively execute the "old" (stale) branch targets. This creates a **speculative execute-after-free** primitive, allowing an attacker to hijack speculative control flow even in the presence of modern software defenses like FineIBT.
## Exploitation
- **Status:** PoC available (demonstrated by researchers against Linux kernel).
- **Complexity:** High (requires precise timing and microarchitectural manipulation).
- **Attack Vector:** Local (unprivileged user targeting kernel or JIT-enabled process).
## Impact
- **Confidentiality:** High (Leakage of sensitive data, such as root password hashes, at rates of ~5.5 KB/sec).
- **Integrity:** None (Speculative execution does not modify architectural state).
- **Availability:** None.
## Remediation
### Patches
- **Linux Kernel:** Mitigations integrated into the kernel (refer to CVE-2026-64507).
- **Oracle GraalVM:** Mitigations have been implemented by Oracle.
- **Mozilla:** Has not released a direct fix for BTR, opting to rely on "Site Isolation" to contain the impact.
### Workarounds
- **IBPB (Indirect Branch Predictor Barrier):** Forcing an indirect branch predictor barrier during context switches or JIT code invalidation. Note: This carries a significant performance penalty.
- **Disabling JIT:** Disabling JIT compilers (e.g., `net.core.bpf_jit_enable=0` in Linux) mitigates the primary vector but impacts performance severely.
## Detection
- **Indicators of Compromise:** Extremely difficult to detect as the attack leaves no traces in standard logs.
- **Detection methods and tools:** Performance counters (PMUs) can be used to monitor for abnormal branch mispredictions or cache misses, though this is prone to false positives in JIT environments.
## References
- **Vusec Research:** hxxps[://]www[.]vusec[.]net/projects/btr/
- **Technical Paper:** hxxps[://]download[.]vusec[.]net/papers/btr_ccs26[.]pdf
- **Linux CVE Announcement 1:** hxxps[://]lore[.]kernel[.]org/linux-cve-announce/2026072554-CVE-2026-64507-5288@gregkh/
- **Linux CVE Announcement 2:** hxxps[://]lore[.]kernel[.]org/linux-cve-announce/2026072554-CVE-2026-64508-fe26@gregkh/
- **Intel Security Guidance:** hxxps[://]www[.]intel[.]com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/indirect-branch-predictor-barrier[.]html