New Spectre Variant Exploits JIT Compilers in Intel-Based Linux Systems
Researchers from Vrije Universiteit (Netherlands) and Scuola Superiore Sant’Anna (Italy) have uncovered a new Spectre variant, dubbed Branch Target Reuse (BTR), which exploits speculative execution in just-in-time (JIT) compilers. The attack targets Intel-based Linux systems, demonstrating practical proof-of-concept (PoC) exploits that can leak sensitive data, including root password hashes, even with existing defenses like cBPF.
Spectre and Meltdown, first disclosed in 2017, exposed critical flaws in modern processors’ speculative execution, allowing side-channel attacks to extract data via indirect system observations. While mitigations were deployed, performance tradeoffs and incomplete fixes left vulnerabilities open to new variants.
BTR exploits the Branch Target Buffer (BTB), where processors store recurring execution patterns. When a JIT compiler reuses memory addresses for different code, the CPU may briefly mispredict branches, creating a window for attackers to extract data. The researchers achieved leakage rates of 5.7 KB/sec (Raptor Cove) and 5.4 KB/sec (Lion Cove), sufficient to exfiltrate sensitive information.
Linux kernel developers and Oracle have released patches, assigning the vulnerabilities CVE-2026-64507 and CVE-2026-64508. Mozilla has also adjusted defenses, though mitigations like IBPB may impact performance. The findings were peer-reviewed and accepted for presentation at ACM CCS 2026 in The Hague this November.
Oracle Linux cybersecurity rating report: https://www.rankiteo.com/company/oracle-linux
The Linux Foundation cybersecurity rating report: https://www.rankiteo.com/company/the-linux-foundation
"id": "ORATHE1790785698",
"linkid": "oracle-linux, the-linux-foundation",
"type": "Vulnerability",
"date": "11/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Technology/Software',
'location': 'Global',
'name': 'Linux Kernel Developers',
'type': 'Open-Source Project'},
{'industry': 'Technology/Software',
'location': 'Global',
'name': 'Oracle',
'size': 'Large',
'type': 'Corporation'},
{'industry': 'Technology/Software',
'location': 'Global',
'name': 'Mozilla',
'size': 'Large',
'type': 'Corporation'}],
'attack_vector': 'Speculative Execution Exploit (Branch Target Buffer - BTB)',
'data_breach': {'data_exfiltration': 'Yes (via side-channel attack)',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive system data (e.g., '
'root password hashes)'},
'description': 'Researchers from Vrije Universiteit (Netherlands) and Scuola '
'Superiore Sant’Anna (Italy) have uncovered a new Spectre '
'variant, dubbed Branch Target Reuse (BTR), which exploits '
'speculative execution in just-in-time (JIT) compilers. The '
'attack targets Intel-based Linux systems, demonstrating '
'practical proof-of-concept (PoC) exploits that can leak '
'sensitive data, including root password hashes, even with '
'existing defenses like cBPF.',
'impact': {'data_compromised': 'Sensitive data, including root password '
'hashes',
'identity_theft_risk': 'High (due to potential exposure of root '
'password hashes)',
'systems_affected': 'Intel-based Linux systems with JIT compilers'},
'investigation_status': 'Ongoing (peer-reviewed findings accepted for '
'presentation at ACM CCS 2026)',
'post_incident_analysis': {'corrective_actions': 'Patches for CVE-2026-64507 '
'and CVE-2026-64508, '
'adjustments to defenses by '
'Mozilla',
'root_causes': 'Exploitation of Branch Target '
'Buffer (BTB) in speculative '
'execution via JIT compiler memory '
'address reuse'},
'recommendations': 'Apply patches for CVE-2026-64507 and CVE-2026-64508, '
'evaluate performance tradeoffs of mitigations like IBPB, '
'and monitor for further Spectre variant developments.',
'references': [{'source': 'ACM CCS 2026'},
{'source': 'Researchers from Vrije Universiteit and Scuola '
'Superiore Sant’Anna'}],
'response': {'containment_measures': 'Patches released by Linux kernel '
'developers and Oracle',
'remediation_measures': 'Mitigations like IBPB (though '
'performance impact noted)'},
'title': 'New Spectre Variant Exploits JIT Compilers in Intel-Based Linux '
'Systems',
'type': 'Side-Channel Attack',
'vulnerability_exploited': ['CVE-2026-64507', 'CVE-2026-64508']}