A recently discovered variant of the Spectre v2 vulnerability has been found to threaten Intel, AMD, and Arm processors. This new risk, dubbed Branch Target Reuse (BTR), was uncovered by researchers from Vrije Universiteit Amsterdam and Scuola Superiore Sant’Anna. The vulnerability exploits just-in-time (JIT) compilers used by operating system kernels, web browsers, and various runtimes.
Branch Target Reuse: A Deeper Dive
BTR allows attackers with code execution capabilities on a machine to potentially extract sensitive data from memory, including password hashes. The attack is particularly potent when launched from malicious web pages, although a full browser exploit has yet to be developed. The root of the vulnerability lies in how processors handle code changes during runtime. Specifically, while modern CPUs maintain code coherence, they may not refresh indirect branch prediction entries.
This oversight creates a scenario where stale predictions can be exploited in JIT engines, allowing an attacker to hijack speculative execution into new code at old offsets. This technique, known as speculative execute-after-free, has been demonstrated against various environments, including the Linux kernel.
Exploiting the Linux Kernel and Browsers
In their experiments, the researchers crafted exploits targeting the Linux kernel, specifically leveraging classic BPF (cBPF). While eBPF JIT is restricted to privileged users, cBPF remains accessible to unprivileged programs and is widely used in applications like Docker and Chrome for filtering tasks. The exploit effectively bypasses existing mitigations on modern Intel CPUs, leaking sensitive information even from fully updated systems.
Browser environments are also vulnerable. In Firefox, a malicious site could execute JavaScript code to exploit shared address spaces, potentially leaking data at considerable rates. The researchers’ proof-of-concept showed that in Firefox’s SpiderMonkey engine, stale branch entries could be reused long enough to leak data. However, a complete browser exploit remains undeveloped.
Mitigation and Industry Response
The vulnerability has been reported to affected hardware and software vendors, who recognize the need for software-based mitigations. Existing mechanisms like the indirect branch prediction barrier (IBPB) can reduce BTR risks, and Linux developers have introduced an x86 mitigation that applies an IBPB when reusing memory regions for cBPF programs.
Despite these efforts, complete protection requires hardware-level updates. Current CPUs lack a mechanism to keep branch predictors aligned with memory code, leaving systems vulnerable until such features are implemented. Some mitigations, like IBT and BTI, complicate exploitation but do not wholly eliminate it. Notably, only Intel’s Lion Cove generation is free from the observed race condition.
SecurityWeek reached out to Intel, AMD, and Arm for comments. While AMD claims the research does not expose new vulnerabilities in its products, Intel and Arm have yet to respond. As industry efforts continue to address this issue, users are advised to stay vigilant and apply available software updates.
