Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

New Spectre‑v2 “Branch Target Reuse” (BTR) Attack Bypasses Linux Defenses and Leaks Memory via JIT Engines

Researchers disclosed a Spectre‑v2 BTR variant that defeats current mitigations in Linux kernels, browsers and JIT runtimes, exposing memory contents. The finding highlights the need for continuous vulnerability‑management evidence to satisfy audit and control‑assurance requirements.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

New Spectre‑v2 “Branch Target Reuse” (BTR) Attack Bypasses Linux Defenses and Leaks Memory via JIT Engines

What Happened — Researchers from VUSec and Scuola Superiore Sant'Anna disclosed a new Spectre‑v2 variant, dubbed Branch Target Reuse (BTR). The flaw exploits just‑in‑time (JIT) compilation paths in browsers, language runtimes and the Linux kernel, allowing an attacker to infer kernel‑level memory contents even when existing Spectre mitigations (e.g., retpoline, IBRS) are enabled.

Why It Matters for Trust & Control Assurance

  • The BTR technique demonstrates a gap in the vulnerability‑management control objective: detecting and remediating micro‑architectural flaws that bypass current mitigations.
  • Continuous control‑assurance programs must capture evidence that patches, configuration hardening, and runtime mitigations are applied and verified across all affected assets.
  • Verisq’s Control Mapping capability can automatically align this new finding with the relevant VCF control, generate audit‑ready evidence, and keep your framework mappings up‑to‑date.

Who Is Affected

  • Cloud‑infrastructure providers and SaaS platforms running Linux containers.
  • Browser vendors and developers of language runtimes that embed JIT engines.
  • Enterprises that host web‑facing services on Linux‑based systems.

Recommended Actions

  • Inventory all Linux hosts and JIT‑enabled runtimes in scope.
  • Verify that the latest kernel patches addressing Spectre‑v2 BTR are applied; if unavailable, apply recommended micro‑code and configuration mitigations (e.g., spec_store_bypass_disable).
  • Integrate the BTR CVE into your vulnerability‑scanning tools and ensure continuous monitoring for re‑exposure.
  • Document remediation steps and collect verifiable evidence for audit readiness.

Source: The Hacker News

Technical Notes

  • Attack vector: Exploits speculative execution through branch target injection in JIT‑compiled code.
  • Affected components: Linux kernel (various distributions), Chromium‑based browsers, Node.js, JavaScriptCore, and other JIT runtimes.
  • Mitigations bypassed: Retpoline, Indirect Branch Restricted Speculation (IBRS), and other Spectre‑v2 defenses.
  • CVE identifiers: Pending assignment; the research community expects multiple CVEs across affected vendors.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →