Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed a new Spectre-v2 attack variant called Branch Target Reuse (BTR). The attack exploits the interaction between self-modifying code in JIT engines (Just-In-Time — on-the-fly compilation) and the processor’s indirect branch prediction mechanism, allowing confidential data to be extracted from Linux kernel memory. Patches for the Linux kernel have already been released — CVE-2026-64507 and CVE-2026-64508 — with the latter receiving a score of 7.0 on CVSS v3.1 according to the Oracle Linux advisory. Linux system administrators should immediately update the kernel and check the status of Spectre-v2 mitigations.
Attack mechanism: stale entries in the branch target buffer
The core of BTR is that modern processors, when code in memory is overwritten (which constantly happens in JIT engines), restore architectural coherence but do not necessarily invalidate stale entries in the Branch Target Buffer (BTB). When a JIT engine frees a memory region with previously compiled code and then allocates new code at the same or an overlapping address, the processor may speculatively jump to the old BTB entry that points to code which no longer exists. According to the researchers, this creates a “transient execute-after-free” primitive that allows an attacker to hijack the speculative control flow.
The attack sequence looks as follows:
- The attacker forces the JIT engine to allocate a “training” code block and direct an indirect branch to it, creating a BTB entry.
- The training block is freed, and in its place (or with partial address overlap) a new target block is allocated.
- When the indirect branch is triggered again, the processor uses the stale BTB entry and speculatively jumps to the old address.
- The result is a hijacked speculative control flow and leakage of confidential data via a cache side channel.
The critical condition is that the stale BTB entry must persist after the JIT engine frees the memory and must be chosen by the branch predictor on the next execution. The attack assumes the ability to run unprivileged code inside the JIT engine.
Affected components and scope of impact
According to the researchers, BTR was tested on three JIT implementations: SpiderMonkey (Mozilla Firefox’s JIT engine), GraalVM, and the Linux kernel’s cBPF JIT — all proved vulnerable, albeit with “noticeably different exploitability characteristics and leakage speed.”
It is important to clarify the scope of confirmed impact. The Oracle entry for CVE-2026-64508 describes the vulnerability specifically in the context of the Linux kernel’s BPF JIT allocator: the problem occurs when memory is reused in packed allocations, and allocations that exceed the pack size are not covered by the predictor-clearing mechanism. This means that the actual impact area in the Linux kernel is narrower than the cross-platform picture presented in the original report. The impact on SpiderMonkey and GraalVM remains confirmed only by the research group — no independent verification of these findings has been found.
Neither CVE-2026-64507 nor CVE-2026-64508 is listed in the CISA KEV catalog. A verified CVSS score for CVE-2026-64507 has not been found. We previously wrote about Linux kernel vulnerabilities being added to the CISA KEV catalog — in this case, the BTR-related vulnerabilities do not have that status.
Exploitation status: PoC, not an in-the-wild attack
The original report mentions two proof-of-concept exploits for the Linux kernel. However, no independent evidence of active exploitation in real-world conditions has been found. The exploitation status should therefore be classified as public PoC available, rather than confirmed exploitation in the wild.
Available patches and mitigations
Patches for both CVEs have already been merged into the mainline Linux kernel. For downstream distributions:
- Oracle Linux 9 and 10 (kernel-uek): update ELSA-2026-500248 was released on September 4, 2026 and includes the fix for CVE-2026-64508.
- GraalVM: Oracle has implemented randomization of the JIT code cache location — the corresponding pull request was merged on August 19, 2026.
- Mozilla Firefox: according to the researchers, Mozilla has considered IBPB-based (Indirect Branch Predictor Barrier) mitigations, but the priority is to complete and roll out site isolation.
Checking mitigation status
Linux system administrators can check the current state of Spectre-v2 protections, including IBPB status, via the sysfs interface, as described in the Linux kernel Spectre documentation:
/sys/devices/system/cpu/vulnerabilities/spectre_v2
This file shows the active mitigation mechanisms and allows you to assess whether the system is protected against attacks based on indirect branch prediction.
Patch prioritization
When planning updates, the differences between the two CVEs should be taken into account. CVE-2026-64508 has a vendor-confirmed score of 7.0 (CVSS v3.1) and a specific update path for Oracle Linux 9/10. For CVE-2026-64507, a verified severity rating and the range of affected versions had not been established at the time of analysis. This does not mean the second vulnerability is less dangerous, but prioritizing patches for CVE-2026-64508 is justified by a more complete information base.
BTR is yet another confirmation that the Spectre class of vulnerabilities continues to generate new attack variants that bypass previously deployed mitigations. The practical takeaway is to update the Linux kernel to a version that includes fixes for CVE-2026-64507 and CVE-2026-64508, check the Spectre-v2 mitigation status via sysfs, and ensure that your IBPB configuration follows your distribution’s recommendations. For environments using GraalVM, update to a version with JIT code cache randomization.