VUSec’s Branch Target Reuse (BTR) research describes a Spectre-v2 attack that can exploit stale indirect-branch predictions after just-in-time (JIT) code is freed and its memory reused. For Linux, the group reports two end-to-end kernel proof-of-concept exploits; its detailed cBPF exploit leaked 8 bytes per second on modern Intel CPUs.
What Branch Target Reuse is
A JIT compiler turns code into machine instructions while a program runs. The processor’s Branch Target Buffer (BTB) stores predicted destinations for indirect branches—jumps whose destination is determined at runtime. VUSec’s BTR research describes how a prediction can outlive the JIT code it originally pointed to.
That mismatch creates a Spectre-v2 technique: a processor may speculatively follow the stale prediction into new code that has reused part of the old code’s memory region. Speculative execution is work the processor performs before it knows whether a branch prediction was correct. Although those operations are later discarded, they can leave measurable traces that expose data.
How stale predictions meet reused JIT code
The attack sequence starts by training an indirect branch to point to a JIT code chunk. After that chunk is freed, new code occupies a reused portion of its address range. If the old BTB entry survives and the processor selects it, speculative execution can enter the new code at an obsolete or misaligned offset.
The reported Linux proof of concept used classic Berkeley Packet Filter (cBPF) programs installed as seccomp filters. VUSec describes training one program and then reusing its memory region for a target program. The stale prediction can then direct speculative execution into the target code.
What VUSec reports for Linux cBPF
VUSec reports building two end-to-end Linux-kernel proof-of-concept exploits. Its detailed cBPF exploit achieved a leakage rate of 8 bytes per second on modern Intel CPUs. That rate belongs to this specific exploit and platform scope.
In a separate demonstration, VUSec recovered a root password hash from the su process after su root loaded the hash into memory. The demonstration illustrates the research result; it does not turn the reported proof of concept into evidence of widespread exploitation.
How SpiderMonkey and GraalVM differ
VUSec reports feasible BTR attacks and a proof of concept for SpiderMonkey, the JavaScript engine used in Firefox. The group says an end-to-end browser exploit requires further work; its Linux cBPF rate does not describe SpiderMonkey.
For GraalVM, VUSec reports stable address reuse and speculative access beyond a masking operation. In its experiments, compilation and garbage collection erased BTB entries before they could be used. VUSec describes Oracle’s approach as randomizing JIT code-cache locations to hinder region reuse.
VUSec also says Mozilla considered IBPB-based measures while prioritizing completion and deployment of site isolation. These responses differ by implementation: the findings do not transfer the Linux cBPF exploit’s measured rate to either runtime.
The Linux mitigation VUSec describes
VUSec says Linux kernel developers upstreamed an x86 mitigation that issues an Indirect Branch Prediction Barrier (IBPB) on all cores when a cBPF program reuses a previously executed cBPF/eBPF region. The mitigation also discourages that reuse. VUSec says it applies whether or not Indirect Branch Tracking (IBT) is enabled.