⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

September 29, 2026

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses Ravie LakshmananSep 29, 2026Vulnerability / Hardware Security A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre-v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida said in an accompanying paper. "In JIT engines, these stale targets can outlive the original…

CVEs: CVE-2026-64507, CVE-2026-64508