Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Branch Target Reuse, BTR: New Spectre V2 Attack Targeting JIT Compilers

Дата публикации: 29-09-2026 17:00:00

It's been a while since any new Spectre vulnerabilities have come to light but that's changing today. The embargo has now lifted on BTR, Branch Target Reuse as a new Spectre-V2 attack affecting just-in-time (JIT) compilers...

Основное содержимое страницы с новостью.

LINUX SECURITY

It's been a while since any new Spectre vulnerabilities have come to light but that's changing today. The embargo has now lifted on BTR, Branch Target Reuse as a new Spectre-V2 attack affecting just-in-time (JIT) compilers.

Security researchers at VUSec have announced today Branch Target Reuse as a Spectre-V2 attack in JIT engines affecting the Linux kernel with BPF, Oracle's GraalVM, and also the Mozilla SpiderMonkey JavaScript engine for Firefox.

BTR amounts to a speculative execute-after-free primitive with JIT compilers when not invalidating stale indirect branch prediction entries. One of the end-to-end exploits developed by VUSec is for leaking arbitrary memory on modern Intel CPUs in bypassing all enabled mitigations. All processors evaluated by the VUSec team were found to be impacted by Branch Target Reuse including Intel, AMD, and Arm hardware.

BTR overview

Hardware vendors are encouraging existing mitigation mechanisms. In July when this was privately disclosed, the Linux kernel landed patches to enabling Indirect Branch Predictor Barrier (IBPB) flush on BPF JIT allocations and support in the BPF kernel code for hardening against JIT spraying. Back in July I covered the kernel changes at the time in Linux 7.2-rc2 BPF Code Being Hardened Against JIT Spraying Attacks. Thus no new Linux kernel mitigations out today as the BPF changes have been mainlined since July and also back-ported already to stable kernel versions.

For Oracle GraalVM, randomizing JIT code-cache locations is being done to hinder BTR. Mozilla is said to have evaluated IBPB-based mitigations for SpiderMonkey but instead prioritizing work on site isolation capabilities.

Those wanting to learn more about BTR can do so at VUSec.net.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses09.2329-09-2026
2Branch Target Reuse, nový útok typu Spectre v2 cílící na JIT kompilátory09.1930-09-2026
3iTPROTECT выпустил новую версию iTPROTECT Scout08.0128-09-2026
4iTProtect выпустил новую версию iTProtect Scout07.7928-09-2026
5iTProtect выпустил новую версию iTProtect Scout07.7928-09-2026
6Citrix Netscaler: Kritische Sicherheitslücken erlauben Codeeinschleusung09.0327-09-2026
7AMD Posts GCC Compiler Patches For AVX10V1AUX ISA Support011.8524-09-2026
8OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted08.3130-09-2026
9Redox OS Adds IO_uring-Like API, NUMA & Gets QEMU Working014.9325-09-2026
10Какие наши продукты задевает эта CVE? Я продолжил заброшенный Minefield и нашёл, что он читал SBOM задом наперёд0926-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 9.13. Источник: www.phoronix.com.