Spectre bug is back, this time to haunt JIT engines

← Back to the feed

Spectre bug is back, this time to haunt JIT engines

The Register · 1 hour ago

Researchers in the Netherlands and Italy have identified Branch Target Reuse (BTR), a new Spectre variant that can target just-in-time (JIT) compilers. It exploits old indirect branch prediction entries left behind when JIT code is replaced, potentially allowing an attacker to infer sensitive data through speculative execution.

The researchers demonstrated proof-of-concept attacks on an Intel-based Linux kernel, extracting a root password hash despite a cBPF defence. They estimate leakage rates of 5.7 KB per second on Intel Raptor Cove chips and 5.4 KB per second on Lion Cove chips. Linux kernel developers and Oracle have added mitigations, while Mozilla is prioritising site isolation; stronger measures such as IBPB can reduce risk but may affect performance.

  • A new Spectre variant can exploit stale branch predictions in JIT engines.
  • Tests extracted a Linux root password hash at several KB per second.
  • Linux and Oracle have mitigations; stronger defences may affect performance.

Research Science

Read the full article at the source →