Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux Kernel Memory Despite Existing Defenses (CVE-2026-64507, CVE-2026-64508)
Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux (TL-2026-2796), also tracked as Branch Target Reuse, is a high-severity software vulnerability scored CVSS 5.5, first published 2026-09-29. It has no confirmed attribution, affects Linux Linux kernel (x86 BPF JIT), references 2 CVEs (CVE-2026-64507, CVE-2026-64508), maps to 4 MITRE ATT&CK techniques (T1003.008, T1005, T1203), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-2796
- Threat ID
- TL-2026-2796
- Also known as
- Branch Target Reuse, BTR, Spectre-BTR
- Severity
- HIGH
- CVSS
- 5.5
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- cloud, technology, government administration, finance, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux
Malware and tooling: Spectre
Researchers from VUSec (VU Amsterdam) and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a Spectre-v2 variant in which stale indirect branch prediction entries survive JIT code-cache reuse, giving a transient execute-after-free primitive. Two end-to-end exploits via the Linux kernel's unprivileged classic BPF (cBPF) JIT recover the root password hash in about 3-5 minutes on fully patched Intel systems; Linux fixes are merged.
How Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux works
Branch Target Reuse (BTR) is a Spectre-v2 variant described in the paper 'Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries' (Sander Wiebing, Yuhui Zhu, Alessandro Biondi, Cristiano Giuffrida; VUSec and Scuola Superiore Sant'Anna; accepted to ACM CCS 2026; embargo lifted 2026-09-29). The root cause is that modern CPUs restore architectural code coherence after self-modifying code but do not necessarily invalidate stale indirect branch prediction entries. In JIT engines, those stale targets outlive the original code and are reused when the code cache is repopulated, yielding a transient 'execute-after-free' primitive that hijacks speculative control flow into newly generated code at obsolete offsets.
The attack proceeds in four steps: (1) train a victim indirect branch to jump into attacker-controlled JIT code, (2) get that JIT chunk deallocated, (3) arrange for new code to be emitted over the same addresses, and (4) trigger the branch again so the CPU speculatively follows the stale BTB entry into misaligned offsets of the reallocated JIT memory. Against the Linux kernel, the exploit uses unprivileged classic BPF programs (created as seccomp filters for the training and target chunks) to train the prediction, free the original program, and place a different program in the reused memory. Two end-to-end exploits leak kernel memory at roughly 8 bytes per second and recover the root password hash in about 3 minutes on Intel Raptor Cove and about 5 minutes on Lion Cove, with default protections enabled. An adaptation defeats BPF constant blinding by encoding attacker bytes in forward jump offsets (a technique from Maisuradze et al., 2016) instead of 4-byte immediates, creating misaligned gadgets that decode differently at alternate alignment boundaries; the hash is still recovered within 5 minutes.
The behaviour was confirmed on every CPU tested, spanning Intel, AMD and Arm, and against three JIT engines: the Linux kernel cBPF JIT, Mozilla Firefox's SpiderMonkey (WebAssembly literal pools via f64.const; estimated tens of bytes per second, full browser exploit not achieved), and Oracle GraalVM (jumping past masking operations that protect sandbox boundaries into unmasked memory access). The same group had previously published an 'Interrupt Injection' attack in August 2026.
Mitigations: the Linux kernel fixes are CVE-2026-64507 ('x86/bugs: Enable IBPB flush on BPF JIT allocation', issuing an IBPB flush on BPF JIT memory reuse when Spectre-v2 mitigations are in use, skipped if the BPF dispatcher already uses retpolines, and only when BPF JIT is enabled) and CVE-2026-64508 (BPF hardening against JIT spraying by flushing branch predictors before reusing JIT memory). Both were published 2026-07-25 (OSV record modified 2026-08-21) and fixed in stable releases 6.1.183, 6.6.145, 6.12.97, 6.18.39 and 7.1.4 (affected since 5.18.0), and in mainline 7.2-rc2. Debian shipped fixes via DSA-6405-1, DLA-4724-1 and DLA-4777-1 (Bullseye not affected). Oracle GraalVM randomizes JIT code-cache locations; Mozilla is relying on site isolation and considering IBPB-based mitigations. Third-party trackers list CVE-2026-64507 at CVSS 5.5 (Medium); the sources reviewed do not publish a CVSS vector and no in-the-wild exploitation is reported. A public proof of concept and demo video accompany the research.
MITRE ATT&CK techniques used in TL-2026-2796
Credential Access
T1003.008 /etc/passwd and /etc/shadow; T1212 Exploitation for Credential Access
Collection
Execution
Affected products and versions in Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux
- Linux — Linux kernel (x86 BPF JIT)
Vulnerable versions: 5.18.0 to before 6.1.183; 6.2.0 to before 6.6.145; 6.7.0 to before 6.12.97; 6.13.0 to before 6.18.39; 6.19.0 to before 7.1.4
Fixed in: 6.1.183; 6.6.145; 6.12.97; 6.18.39; 7.1.4; 7.2-rc2 (mainline) - Mozilla — Firefox (SpiderMonkey JIT)
Vulnerable versions: Tested by researchers; version not stated - Oracle — GraalVM
Vulnerable versions: Tested by researchers; version not stated
Fixed in: JIT code-cache location randomization - Intel — Processors (Raptor Cove, Lion Cove confirmed)
Vulnerable versions: Raptor Cove; Lion Cove - AMD — Processors with indirect branch prediction
Vulnerable versions: Confirmed vulnerable; models not detailed - Arm — Processors with indirect branch prediction
Vulnerable versions: Confirmed vulnerable; models not detailed
Remediation for Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux
Patches
- Linux kernel: x86/bugs IBPB flush on BPF JIT allocation (CVE-2026-64507) and BPF JIT-spraying hardening (CVE-2026-64508)
- Debian: DSA-6405-1, DLA-4724-1, DLA-4777-1 (e.g. 6.1.187-1, 6.12.107-1~deb12u1, 6.12.111-1)
- Oracle GraalVM: randomized JIT code-cache locations
Immediate actions
- Upgrade the Linux kernel to a release containing the CVE-2026-64507 and CVE-2026-64508 fixes (6.1.183, 6.6.145, 6.12.97, 6.18.39, 7.1.4 or later; mainline 7.2-rc2+)
- Apply OS and CPU microcode/firmware updates from the hardware vendor
Workarounds
- Restrict unprivileged BPF where feasible (kernel.unprivileged_bpf_disabled) until patched
- Do not disable Spectre-v2 mitigations (mitigations=off) on multi-tenant or untrusted-code hosts
Longer-term hardening
- Keep Spectre-v2 mitigations (IBPB/retpoline) enabled on hosts that run BPF JIT
- Deploy Firefox site isolation and track Mozilla IBPB-based mitigation work
CVEs associated with Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux
Timeline of Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux
- Linux stable fixes released in 6.1.183, 6.6.145, 6.12.97, 6.18.39 and 7.1.4 (mainline fix in 7.2-rc2); vulnerable range starts at 5.18.0
- CVE-2026-64507 (x86/bugs IBPB flush on BPF JIT allocation) and CVE-2026-64508 (BPF JIT-spraying hardening) published for the Linux kernel
- OSV record for CVE-2026-64508 last modified, listing six fix commits across the affected stable branches
- The Hacker News, BleepingComputer and HWBusters publish coverage; Debian tracker lists fixes via DSA-6405-1, DLA-4724-1 and DLA-4777-1
- GraalVM randomizes JIT code-cache locations; Mozilla prioritizes site isolation and considers IBPB-based mitigations for SpiderMonkey; Linux issues IBPB on BPF JIT allocation
- Researchers report BTR on Intel, AMD and Arm CPUs and in SpiderMonkey (WebAssembly f64.const literal pools) and GraalVM (bypass of sandbox masking); no complete browser exploit achieved
- Two end-to-end Linux cBPF exploits recover the root password hash in ~3 minutes on Raptor Cove and ~5 minutes on Lion Cove at ~8 bytes/s, including a constant-blinding bypass via jump-offset encoding
- Public proof of concept and demo video released alongside the paper; exploits target the Linux cBPF JIT, with SpiderMonkey and GraalVM also shown exposed
- Embargo lifted; VUSec and Scuola Superiore Sant'Anna publish the Branch Target Reuse research (accepted to ACM CCS 2026)
Sources cited for Spectre-v2 Branch Target Reuse (BTR) Attack Leaks Linux
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
- New Spectre v2 attack variant leaks Linux root password hash in minutes
- Branch Target Reuse Turns JIT Compilers Into a Spectre v2 Launchpad, Leaking Root Hashes in Minutes
- VUSec: Branch Target Reuse (BTR) project page
- OSV: CVE-2026-64507
- OSV: CVE-2026-64508
- Debian Security Tracker: CVE-2026-64507
- INCIBE-CERT early warning: CVE-2026-64507
More in vulnerability
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)
- Docker CopyEscape (CVE-2026-17106): docker cp / sbx cp flaw lets malicious containers overwrite host files
Detection coverage for TL-2026-2796
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2796 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.