Ethical Hacking News
A new Spectre-v2 BTR attack has been discovered, which can leak Linux memory despite existing defenses. The attack, which affects multiple CPU vendors, can bypass software hardening and reach misaligned gadgets. The Linux kernel has released mitigations for the vulnerability, but the attack highlights the ongoing need for continuous monitoring and patching of software systems to prevent vulnerabilities from being exploited. This article provides an in-depth analysis of the attack and its implications for cybersecurity professionals and organizations.
The Spectre-v2 BTR attack is a new vulnerability variant that affects Just-In-Time (JIT) engines in web browsers, language runtimes, and the operating system kernel. Attackers can hijack transient control flow to newly generated code at obsolete offsets, bypassing software hardening or reaching misaligned gadgets. The attack allows attackers to leak and recover the root password hash within minutes from a fully patched Intel system with default protections enabled. The attack affects multiple CPU vendors and was found to be effective against SpiderMonkey (Mozilla Firefox's JIT engine), GraalVM, and the Linux kernel's cBPF JIT. The Linux kernel has released mitigations for the vulnerability, and organizations must stay vigilant and proactive in securing their systems and data.
The cybersecurity landscape has witnessed numerous breaches and vulnerabilities in recent years, and one of the most concerning ones is the Spectre-v2 BTR attack. In a recent disclosure, a group of academics from VUSec and Scuola Superiore Sant'Anna revealed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR).
According to the researchers, the key insight is that while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries. This allows attackers to hijack transient control flow to newly generated code at obsolete offsets, bypassing software hardening or reaching misaligned gadgets. The researchers noted that this allows attackers to leak and recover the root password hash within minutes from a fully patched Intel system with default protections enabled.
The researchers evaluated the BTR attack against SpiderMonkey (the JIT engine of Mozilla Firefox), GraalVM, and the Linux kernel's cBPF JIT, all of which have been found to be affected. However, the exploitability characteristics and leakage rates of the attack varied across the different systems. The researchers found that GraalVM hinders region reuse by randomizing JIT code-cache locations, while Mozilla considered IBPB (Indirect Branch Predictor Barrier)-based mitigations but is currently prioritizing the completion and deployment of site isolation.
The disclosure comes nearly two months after MIT CSAIL researchers Daniƫl Trujillo and Mengjia Yan disclosed a speculative execution attack technique called Interrupt Injection that can bypass Spectre v2 defenses and leak arbitrary kernel memory from Intel- and AMD-based Linux systems. This highlights the ongoing battle between cybersecurity professionals and attackers, with new vulnerabilities and exploits emerging regularly.
In response to the Spectre-v2 BTR attack, the Linux kernel has released mitigations for the vulnerability, with CVE-2026-64507 and CVE-2026-64508 being the latest patches. However, the attack highlights the need for continuous monitoring and patching of software systems to prevent vulnerabilities from being exploited. It also underscores the importance of software hardening and mitigations, such as IBPB, to prevent attackers from bypassing security controls.
The Spectre-v2 BTR attack is a reminder of the ongoing cat-and-mouse game between cybersecurity professionals and attackers. As new vulnerabilities and exploits emerge, it is essential for organizations to stay vigilant and proactive in securing their systems and data. By staying informed about the latest vulnerabilities and exploits, organizations can take steps to prevent breaches and protect their assets.
In conclusion, the Spectre-v2 BTR attack highlights the ongoing threat landscape in the cybersecurity world. The attack demonstrates the creativity and persistence of attackers, who continue to find new ways to exploit vulnerabilities in software systems. However, it also underscores the importance of continuous monitoring and patching, as well as software hardening and mitigations, to prevent vulnerabilities from being exploited. By staying informed and proactive, organizations can take steps to protect their assets and prevent breaches.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Spectre-v2-BTR-Attack-Leaks-Linux-Memory-Despite-Existing-Defenses-ehn.shtml
https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
Published: Tue Sep 29 13:07:00 2026 by llama3.2 3B Q4_K_M