Security1 publisher2 min readPublished
Linux, GraalVM and Mozilla take three different routes against Branch Target Reuse
Linux has merged two kernel fixes, CVE-2026-64507 and CVE-2026-64508, for the Branch Target Reuse Spectre-v2 variant that leaks memory through JIT engines. GraalVM and Firefox took other routes, so a host's coverage depends on which JIT engine it lets untrusted code run in.
The Watch ยท Security desk
What happened
- Researchers from VUSec and Scuola Superiore Sant'Anna found the flaw in JIT engines used by browsers, language runtimes and the OS kernel, across more than one CPU vendor.
- The attacker must already be able to run unprivileged code inside a JIT engine, and the goal is reading sensitive data from the host around it.
- Firefox's SpiderMonkey, GraalVM and the Linux kernel's cBPF JIT all proved vulnerable, with markedly different exploitability and leak rates.
- Two kernel exploits recovered the root password hash within minutes on a fully patched Intel system running default protections.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Linux hosts where unprivileged users can reach the kernel cBPF JIT remain open to root-hash theft on Intel until the merged kernel fixes are deployed, because the default protections did not stop the lab exploits.
- constraint Firefox users have no BTR-specific barrier for now. Their protection depends on how quickly Mozilla finishes and ships site isolation.
- constraint GraalVM's randomization targets the address-reuse step. The stale predictor entry that the CPU keeps after a free is not touched by that change.
The attack chain runs through the JIT's code cache. The attacker gets the engine to allocate a training chunk and forces a victim indirect branch to jump into it, planting a branch target buffer (BTB) entry that points at that chunk's entry point [8]. The attacker then forces the chunk to be freed and a new target chunk allocated partly over the same address [8]. When the branch fires again, the CPU follows the stale BTB entry and speculatively jumps to the old entry point [8]. That old entry point now sits at an obsolete offset inside newly generated code [4].
"The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," said researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi and Cristiano Giuffrida [3]. Spectre v2, part of the class discovered in 2017, poisons indirect branch prediction so a victim branch speculatively runs an attacker-chosen gadget, and the data is read back through cache timing [15][14]. In BTR the wrong target comes from the engine's own freed code, reused when the code cache is repopulated [4].
The landing point explains why hardening already built into JITs does not stop it. "By redirecting control flow to an architecturally invalid entry point, the attacker can bypass Spectre hardening mitigations or execute misaligned instructions, ultimately disclosing secret data," the researchers said [9]. Two conditions have to hold. The stale BTB entry must survive the free without being invalidated or replaced, and the branch predictor must select it [10].
The fixes differ by engine. The kernel mitigations have been released and merged [11]. GraalVM went after the address reuse the chain depends on. "GraalVM instead hinders region reuse by randomizing JIT code-cache locations," the researchers said [12]. Mozilla has put a barrier aside for now. The researchers said Mozilla considered mitigations based on the Indirect Branch Predictor Barrier (IBPB) but is currently prioritizing the completion and deployment of site isolation [13].
On hardware scope, the researchers describe BTR as affecting multiple CPU vendors [1]. The report does not say which ones beyond Intel, the platform the working kernel exploits ran on [6]. BTR is a lab disclosure from academic teams [1]. It came nearly two months after MIT CSAIL researchers disclosed a speculative execution attack of their own [16].
What to watch
- Whether CPU vendors publish microcode or guidance that invalidates stale BTB entries when JIT code is freed, and which vendors the paper lists beyond Intel.
- Whether Mozilla revisits IBPB for Firefox or ships site isolation first.
- Backports of CVE-2026-64507 and CVE-2026-64508 into distribution stable kernels.