AMD, Linux Foundation and Oracle: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

AMD, Linux Foundation and Oracle: New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

New Spectre v2 Variant "BTR" Exploits CPU Branch Prediction Flaws Across Intel, AMD, and Arm

Researchers from VUSec (Vrije Universiteit Amsterdam) and Scuola Superiore Sant’Anna have uncovered a new Spectre v2 attack variant, dubbed Branch Target Reuse (BTR), affecting CPUs from Intel, AMD, and Arm. The flaw exploits weaknesses in just-in-time (JIT) compilers used by operating system kernels, web browsers, and runtimes, enabling attackers to steal sensitive data such as password hashes from memory.

How BTR Works

BTR leverages stale indirect branch prediction entries in CPUs, which persist even after code is modified. In JIT engines, these outdated predictions can be reused when new code is written to the same memory location, creating a "speculative execute-after-free" primitive. This allows attackers to hijack speculative execution, bypassing security mitigations.

The researchers demonstrated end-to-end exploits against the Linux kernel, successfully leaking the root password hash at a rate of 8 bytes per second enough to extract critical data even on fully updated systems. The attack also affects Firefox’s SpiderMonkey engine and Oracle’s GraalVM, though browser-based exploits remain unproven.

Impact and Mitigations

  • Linux Kernel: Exploits cBPF (used in Docker, Chrome, and seccomp filters) to bypass Spectre v2 defenses. A mitigation has been introduced, triggering an Indirect Branch Prediction Barrier (IBPB) when BPF code is reused.
  • Browsers: Firefox is vulnerable due to incomplete site isolation, allowing malicious JavaScript to potentially access data from other tabs.
  • GraalVM: Could bypass memory masking in its strictest sandbox mode, though exploitation is hindered by garbage collection.
  • Hardware: CPU vendors (Intel, AMD, Arm) acknowledge the issue but state that software-level fixes are required. Existing protections like IBPB can mitigate BTR, but hardware-based sync mechanisms are needed for a permanent solution.

Vendor Responses

  • AMD stated the research does not reveal a new vulnerability, citing existing Spectre v2 mitigations.
  • Intel and Arm have not yet responded to requests for comment.

The flaw underscores persistent risks in speculative execution, with researchers warning that no current CPU fully synchronizes branch prediction with runtime code changes. While newer Intel CPUs (Lion Cove and later) reduce exposure, older systems remain vulnerable.

Source: https://www.securityweek.com/new-spectre-v2-variant-exposes-intel-amd-arm-cpus-to-data-leaks/

AMD TPRM report: https://www.rankiteo.com/company/amd

Linux Foundation TPRM report: https://www.rankiteo.com/company/the-linux-foundation

Oracle TPRM report: https://www.rankiteo.com/company/oracle

"id": "amdtheora1790743474",
"linkid": "amd, the-linux-foundation, oracle",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Semiconductors',
                        'name': 'Intel',
                        'type': 'Hardware Manufacturer'},
                       {'industry': 'Technology/Semiconductors',
                        'name': 'AMD',
                        'type': 'Hardware Manufacturer'},
                       {'industry': 'Technology/Semiconductors',
                        'name': 'Arm',
                        'type': 'Hardware Manufacturer'},
                       {'industry': 'Software/Open Source',
                        'name': 'Linux Kernel',
                        'type': 'Operating System'},
                       {'industry': 'Software/Internet',
                        'name': 'Mozilla Firefox',
                        'type': 'Web Browser'},
                       {'industry': 'Software/Enterprise',
                        'name': 'Oracle GraalVM',
                        'type': 'Runtime Environment'}],
 'attack_vector': 'Exploitation of CPU branch prediction flaws via JIT '
                  'compilers',
 'data_breach': {'data_exfiltration': 'Yes (demonstrated at 8 bytes per '
                                      'second)',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Password hashes',
                                              'Sensitive memory data']},
 'description': 'Researchers from VUSec and Scuola Superiore Sant’Anna '
                'uncovered a new Spectre v2 attack variant, dubbed Branch '
                'Target Reuse (BTR), affecting CPUs from Intel, AMD, and Arm. '
                'The flaw exploits weaknesses in just-in-time (JIT) compilers '
                'used by operating system kernels, web browsers, and runtimes, '
                'enabling attackers to steal sensitive data such as password '
                'hashes from memory. BTR leverages stale indirect branch '
                "prediction entries in CPUs, creating a 'speculative "
                "execute-after-free' primitive that bypasses security "
                'mitigations. End-to-end exploits were demonstrated against '
                'the Linux kernel, leaking the root password hash at a rate of '
                '8 bytes per second.',
 'impact': {'data_compromised': 'Sensitive data (e.g., password hashes)',
            'identity_theft_risk': 'High (password hashes and sensitive data '
                                   'exposure)',
            'operational_impact': 'Potential bypass of Spectre v2 defenses, '
                                  'speculative execution hijacking',
            'systems_affected': ['Linux kernel',
                                 'Firefox’s SpiderMonkey engine',
                                 'Oracle’s GraalVM']},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Persistent risks in speculative execution highlight the '
                    'need for hardware-level synchronization of branch '
                    'prediction with runtime code changes. Software '
                    'mitigations like IBPB are temporary solutions.',
 'post_incident_analysis': {'corrective_actions': ['Software mitigations '
                                                   '(e.g., IBPB)',
                                                   'Hardware redesign for '
                                                   'future CPUs'],
                            'root_causes': 'Stale indirect branch prediction '
                                           'entries in CPUs, lack of '
                                           'synchronization between branch '
                                           'prediction and runtime code '
                                           'changes'},
 'recommendations': ['Apply Linux kernel patches triggering IBPB for BPF code '
                     'reuse',
                     'Enhance browser site isolation (e.g., Firefox)',
                     'Monitor for hardware-based fixes from CPU vendors',
                     'Audit JIT compilers for similar vulnerabilities'],
 'references': [{'source': 'VUSec (Vrije Universiteit Amsterdam) and Scuola '
                           'Superiore Sant’Anna'}],
 'response': {'containment_measures': ['Indirect Branch Prediction Barrier '
                                       '(IBPB) for BPF code reuse'],
              'remediation_measures': ['Software-level fixes (e.g., IBPB '
                                       'triggers)',
                                       'Hardware-based sync mechanisms '
                                       '(future)']},
 'title': "New Spectre v2 Variant 'BTR' Exploits CPU Branch Prediction Flaws "
          'Across Intel, AMD, and Arm',
 'type': 'Spectre v2 Attack Variant',
 'vulnerability_exploited': 'Stale indirect branch prediction entries (Branch '
                            'Target Reuse - BTR)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.