TL;DR
Researchers at VUSec have published full details and proof-of-concept code for Branch Target Reuse (BTR), a new Spectre-v2 attack on just-in-time (JIT) compilers. Their end-to-end exploit leaked the Linux root password hash from kernel memory on modern Intel CPUs, bypassing all enabled mitigations. The Linux kernel has patched the issue under CVE-2026-64507 and CVE-2026-64508.
- Product: Linux
- Vulnerabilities: 2 flaws (CVE-2026-64507, CVE-2026-64508)
- Highest severity: Awaiting analysis
- Worst impact: x86/bugs: Enable IBPB flush on BPF JIT allocation
- Status: No confirmed exploitation yet; patches available
- Action: Update to 25dbcd31781e2bc3cd63d873af1fcd06f863a126, cb27f3bf915cc0f20fc0c48da9059304e39ebd35, 9354248fc1c33a844ca1872761f6668b393e8c37, 8a4c8af9ae67eb072d90d1b339f14d27a82bd2a1 (+14) now
| CVE | Type | Fixed in | Status |
|---|---|---|---|
| CVE-2026-64507 | x86/bugs: Enable IBPB flush on BPF JIT allocation | 25dbcd31781e2bc3cd63d873af1fcd06f863a126, cb27f3bf915cc0f20fc0c48da9059304e39ebd35, 9354248fc1c33a844ca1872761f6668b393e8c37 (+9) | Not exploited |
| CVE-2026-64508 | bpf: Support for hardening against JIT spraying | 1fbafd5235ca897b322161659ebe8ba651b00b3b, 6e52c240c43a601b681e3a4e58fc5685114d4726, eed774da601268dae674e14d54a15e3624691f52 (+9) | Not exploited |
Running Infra, AppSec, and SOC teams? Tag Linux kernel alerts by team automatically.
Try Team free for 14 daysWhy the Branch Target Reuse Attack Matters
JIT engines sit inside web browsers, language runtimes, and the operating system kernel. The researchers studied three of them: Linux cBPF, Oracle GraalVM, and SpiderMonkey, the JavaScript engine in Firefox.
The hardware problem is broad. According to the VUSec Branch Target Reuse project page, “No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable.” The team confirmed the behavior on every CPU it tested, from Intel, AMD, and Arm.
The kernel target also matters. Unprivileged programs can still use classic BPF (cBPF). It powers seccomp filters and packet filtering in tools such as Docker and Chrome.
How the Attack Works
Modern CPUs guess where indirect jumps will land and store those guesses in the branch target buffer. JIT engines create and delete code in memory all the time. VUSec explains the core insight: “while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries.”
As a result, an old branch prediction can outlive the code it pointed to. When the JIT engine later places new code at the same address, the CPU may speculatively jump to the stale target. The researchers call this a “speculative execute-after-free primitive.” It lets an attacker steer speculative execution into code at unexpected offsets and leak secrets through side channels.
The Linux Kernel Exploit
The team built a full exploit against Linux cBPF. It leaks memory at about eight bytes per second. That rate sounds slow, but targeted pointer chasing keeps the needed data small. In the demo, the exploit walked kernel structures to find and leak the root password hash. BleepingComputer reports that this took three to five minutes on average on the tested Intel processors.
The researchers also bypassed the kernel’s optional cBPF constant-blinding hardening, which is off by default.
Firefox and GraalVM
In SpiderMonkey, a proof of concept achieved speculative code execution on Intel CPUs. However, VUSec notes that “turning this into an end-to-end browser exploit requires further work.” In GraalVM, the engine’s own garbage collection wiped the needed branch entries before the attack could use them.
Public Proof-of-Concept and Exploitation Status
The technical details and exploit code are now public. VUSec released its Branch Target Reuse research paper, accepted at ACM CCS 2026, along with the BTR proof-of-concept code on GitHub. No exploitation in the wild has been reported.
Affected Systems and Mitigations
Hardware vendors told the researchers that existing mechanisms such as IBPB already help, and that fixes belong in software. The Linux kernel added two fixes:
- CVE-2026-64507: issues an IBPB flush on all cores when a cBPF program reuses a previously executed JIT region.
- CVE-2026-64508: adds support for hardening against JIT spraying.
Oracle now randomizes GraalVM JIT code-cache locations. Mozilla is focusing on finishing site isolation in Firefox instead of IBPB-based fixes.
Update your kernel and software as soon as patches reach your distribution. Features such as Intel IBT and Arm BTI “raise the bar, but do not eliminate the risk,” according to VUSec. Because Branch Target Reuse affects every CPU the team tested, software patches remain the main defense.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!