By Interestana AI Editorial — AI-drafted, human-overseen. How we report
New Spectre-v2 BTR Attack Leaks Linux Memory

A new variant of the Spectre CPU vulnerability, codenamed Branch Target Reuse (BTR), has been disclosed by academics from VUSec and Scuola Superiore Sant'Anna. This variant specifically targets Just-In-Time (JIT) engines found in web browsers, language runtimes, and the operating system kernel, affecting multiple CPU vendors. The researchers demonstrated that BTR can successfully leak sensitive memory contents from Linux systems, even when existing Spectre defenses are in place. The core mechanism of the BTR attack exploits a speculative execution side-channel. Modern CPUs employ branch prediction to anticipate the flow of program execution, which can be a performance optimization. However, this prediction process can inadvertently leave traces in the CPU's microarchitectural state. The BTR attack leverages a technique called Branch Target Injection, where an attacker manipulates the branch predictor to speculatively execute code along a path chosen by the attacker. Crucially, BTR focuses on reusing the target address of a previously executed indirect branch. By carefully crafting specific code sequences, an attacker can trick the CPU into speculatively fetching and processing data from memory locations that should be inaccessible. The leaked data is then recovered by observing changes in the CPU's cache or other microarchitectural states, a technique common to many side-channel attacks. The research highlights that while mitigations like Retpoline and indirect branch restricted speculation (IBRS) have been implemented to counter earlier Spectre variants, BTR demonstrates a novel way to bypass these protections. The academics provided proof-of-concept demonstrations showing the successful exfiltration of data from a Linux kernel environment. This discovery underscores the persistent threat posed by speculative execution vulnerabilities and the ongoing arms race between hardware security features and exploit development. The implications extend to a wide range of software that relies on JIT compilation, including JavaScript engines in browsers, .NET runtimes, and virtual machine monitors. The researchers plan to present their findings at the IEEE Symposium on Security and Privacy, providing detailed technical analysis and further evidence of the attack's efficacy. The disclosure prompts a reassessment of current CPU security architectures and the need for more robust defenses against sophisticated side-channel attacks.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.