Ethical Hacking News
The Spectre bug has returned, targeting JIT engines. Researchers have found a way to exploit stale indirect branch prediction entries, a technique that can be used to commandeer speculative control flow. Linux kernel developers and Oracle have implemented mitigations, but the vulnerability highlights the ongoing threat of Spectre and Meltdown attacks.
The Spectre bug, a previously discovered vulnerability in microarchitecture, has resurfaced, targeting just-in-time (JIT) engines. Researchers have found a way to recover stale indirect branch prediction entries, a technique that can be exploited to commandeer speculative control flow. The vulnerability arises from the way modern CPUs restore architectural code coherence after self-modification. The attack allows an attacker to reveal the root password hash, even with the constant binding defense provided by cBPF. Mitigations have been put in place by Linux kernel developers and Oracle, with assigned CVEs: CVE-2026-64507 and CVE-2026-64508. However, Mozilla has opted to prioritize work on site isolation instead of addressing the issue directly.
The Spectre bug, a previously discovered vulnerability in microarchitecture, has resurfaced, targeting just-in-time (JIT) engines. Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have found a way to recover stale indirect branch prediction entries, a technique that can be exploited to commandeer speculative control flow in a way that avoids some software defenses. This new form of the Spectre bug, dubbed "Branch Target Reuse" (BTR), is the first practical in-place Spectre v2 attack that targets JIT compilers, including Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey.
The vulnerability arises from the way modern CPUs restore architectural code coherence after self-modification. While they invalidate stale direct branch prediction entries, they do not necessarily invalidate stale indirect branch prediction entries, which can outlive the original code and later be reused when the code cache is repopulated. This allows an attacker to exploit the vulnerability by designing two proof-of-concept exploits against an Intel-based Linux kernel that reveal the root password hash, even with the constant binding defense provided by cBPF.
The researchers demonstrated that the expected leakage rate is 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove. This may seem like a slow rate of data leakage, but it is enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system. The authors emphasized that the key insight behind the attack is that stale indirect branch prediction entries can be used to exploit the vulnerability.
Following the disclosure of the findings, Linux kernel developers and Oracle put mitigations in place to address the issue. Two CVEs were assigned: CVE-2026-64507 and CVE-2026-64508. Mozilla, however, has opted to prioritize work on site isolation instead of addressing the issue directly. Strong mitigations like IBPB (Indirect Branch Prediction Barrier) are said to be effective but add complexity and hinder performance.
The Branch Target Reuse paper has been accepted for publication at the ACM Conference on Computer and Communications Security (CCS) 2026, which will be held November 15 through 19 in The Hague, Netherlands.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Spectre-Bug-Returns-A-New-Vulnerability-Haunts-JIT-Engines-ehn.shtml
https://www.theregister.com/security/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines/5299937
https://securityshelf.com/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines/
https://nvd.nist.gov/vuln/detail/CVE-2026-64507
https://www.cvedetails.com/cve/CVE-2026-64507/
https://nvd.nist.gov/vuln/detail/CVE-2026-64508
https://www.cvedetails.com/cve/CVE-2026-64508/
Published: Wed Sep 30 02:42:31 2026 by llama3.2 3B Q4_K_M