← Blog · · df00tech

New Spectre-v2 'BTR' Attack Bypasses Existing Mitigations to Leak Linux Kernel Memory

security-news technique

What was reported

Academic researchers from VUSec and Scuola Superiore Sant'Anna have disclosed a new Spectre-v2 variant they call Branch Target Reuse (BTR). According to the disclosure, the attack targets Just-In-Time (JIT) engines found in web browsers, language runtimes, and operating system kernels, and affects multiple CPU vendors. The researchers describe a key insight into how modern CPUs handle branch target state that allows the existing Spectre-v2 mitigations to be circumvented, though the full technical detail of the bypass was not included in the summary available at publication time.

Why it matters for defenders

Spectre-class attacks exploit speculative execution to leak memory contents across trust boundaries. Because BTR is reported to work "despite existing defenses" and to span JIT engines in browsers, runtimes, and the kernel, it potentially undermines mitigations that organizations have already deployed and relied on for years. The multi-vendor CPU scope means this is not isolated to a single hardware platform, and JIT-heavy software (browsers, Node.js, JVMs, kernel eBPF/JIT subsystems) may be broadly in scope for follow-up analysis. As with prior Spectre variants, practical exploitation is typically complex, but the class of vulnerability is historically difficult to fully remediate.

What defenders should watch for or do now

  • Track vendor advisories (CPU vendors, Linux kernel, major browsers/runtimes) for BTR-specific patches or microcode/mitigation updates once published.
  • Review whether existing Spectre-v2 mitigations (e.g., retpoline, IBRS/eIBRS-style controls, kernel speculation-mitigation flags) are current and confirm vendor guidance on whether they remain effective against this variant.
  • Inventory JIT-reliant components in your environment — browsers, managed-runtime services, and kernel JIT/eBPF usage — as these are called out as the affected surface.
  • Watch academic/vendor channels for the full paper and any proof-of-concept, which will clarify real-world exploitability and detection feasibility.
  • No SIEM detection content is proposed here, as this is a CPU microarchitectural side-channel issue rather than a traditional log-observable technique; monitor for vendor-issued indicators or mitigation status tooling instead.

Developing story

This is net-new intelligence based on an initial disclosure summary, and full technical details, affected CPU models, and patch guidance were not yet available at the time of writing. Defenders should treat this as an early signal and follow up with primary sources as more information emerges. Read the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.