New Spectre-v2 BTR Flaw Lets Linux Memory Leak Even With Patches

Researchers from VUSec and Scuola Superiore Sant’Anna have uncovered a new variant of Spectre-v2 dubbed Branch Target Reuse (BTR), which affects modern CPUs by leaking memory even when systems have existing defenses in place. The vulnerability targets Just-In-Time (JIT) engines in web browsers, language runtimes, and the Linux kernel, and persists across vendors despite patched protections.

What’s New About BTR?

BTR exploits how modern CPUs treat branch target buffer (BTB) entries during speculative execution. Although CPUs refresh architectural code paths after self-modifying code runs, they may leave stale indirect branch prediction entries intact. In the context of JIT engines, these stale entries can survive after code is deallocated and later reused when new code is generated. This oversight enables control-flow to be transiently hijacked, bypassing typical Spectre hardening and allowing data to leak from sensitive locations.

Affected Systems & Impact

The team tested BTR against several JIT engines—Mozilla’s SpiderMonkey, GraalVM, and the Linux kernel’s cBPF JIT—and confirmed all are vulnerable, though some are harder to exploit than others based on their leakage rates and exploitability. One proof-of-concept exploit demonstrated that attackers could extract a root password hash from a fully patched Intel Linux system in just minutes, using default mitigations.

To carry out the attack, an adversary must run unprivileged code inside a JIT environment. The attack flow involves allocating a training chunk to establish BTB entries, freeing it, reusing the memory for target code, and triggering an indirect branch that mispredicts using the stale entry. The misprediction is used to speculatively execute code at a now-invalid address, deviating control flow and leaking secret data via side channels.

What Has Been Done to Mitigate This?

Several defenses have been merged into the Linux kernel following the public disclosure of BTR through two new CVEs. One approach involves Linux kernel changes that address stale BTB entries. GraalVM uses randomized JIT code-cache locations to avoid predictable memory reuse. Mozilla is considering deploying the Indirect Branch Predictor Barrier (IBPB) and putting more effort into site isolation to contain untrusted code.

BTR’s emergence comes shortly after another speculative execution technique called Interrupt Injection was revealed. That earlier attack similarly bypassed many Spectre-v2 defenses to leak kernel memory on both Intel and AMD Linux machines—suggesting that this class of vulnerabilities remains dangerous despite mitigation efforts.

This new vulnerability underscores that Spectre variants are still evolving. Hardening techniques introduced over the years–including site isolation, IBPB, and code cache randomization–are effective in part, but BTR demonstrates that attackers continue to find ways to abuse subtle hardware behavior.

What this means: system maintainers, browser developers, and runtime engine teams need to move fast. Keep machines patched, deploy mitigation layers like IBPB and site isolation, and ensure JIT engines employ randomness in memory allocation and code placement. On the horizon: more formal hardware-level changes may be required to neutralize these speculative-execution attacks at the source.