Intel, AMD and Arm say their IBPB barrier can block Branch Target Reuse, a Spectre v2 variant hitting all three, if JIT software calls it. Each kernel, browser and runtime that rewrites JIT code now has to add that call itself.
Reality
- Evidence55
- Adoption40
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Linux has merged two kernel fixes, CVE-2026-64507 and CVE-2026-64508, for the Branch Target Reuse Spectre-v2 variant that leaks memory through JIT engines. GraalVM and Firefox took other routes, so a host's coverage depends on which JIT engine it lets untrusted code run in.
Reality
- Evidence58
- Adoption40
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
VUsec and Sant'Anna researchers built BTR, a Spectre v2 variant that read a Linux root password hash off two Intel cores in three to five minutes. The Linux kernel fix is merged, and the researchers advise applying operating system and firmware updates.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence50