Skip to content
See the World Through ScienceA project of ALLATRA

Linux and Oracle Patch a New Spectre Flaw in Code Compiled on the Fly

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Extreme close-up photograph of the silicon die of an Intel Skylake-SP Xeon server processor, showing a regular grid of repeating circuit blocks in green and pink.
Magnified silicon from an Intel Xeon server processor. Branch prediction, the hardware behavior the new attack abuses, is built into logic like this (illustrative)."Intel@14nm@Skylake@Skylake-SP(XCC)@Xeon(ES)@QJW5___DSCx10@5x" by FritzchensFritz, via flickr, CC0

Researchers at the VUSec group at VU Amsterdam and at Scuola Superiore Sant'Anna disclosed a new variant of the Spectre-v2 processor attack on Sept. 29, 2026. Fixes have already shipped for the Linux kernel, where they are tracked as CVE-2026-64507 and CVE-2026-64508, and for Oracle's GraalVM runtime.

The flaw sits in just-in-time compilers, the components that build machine code while a program is running. The researchers' advice to system owners is to update the operating system and other software as soon as vendor patches are available; the Linux kernel and Oracle have released theirs.

The group calls the attack Branch Target Reuse. Modern processors remember where an indirect branch last jumped. The researchers found that the record can outlive the code it belonged to: after a just-in-time engine discards a block of generated code and places different code at the same address, the old prediction can still be used. They analyzed the Linux kernel's classic BPF filters, Oracle's GraalVM and Firefox's SpiderMonkey engine. They built two working exploits against the Linux kernel, one of which, they report, reads memory at 8 bytes a second on current Intel processors.

The researchers say they confirmed the underlying behavior on every processor they tested, covering Intel, AMD and Arm. The hardware vendors told the researchers that mechanisms to blunt this class of attack already exist and that mitigations for this variant belong in software. The group notes that classic BPF remains available to unprivileged programs and is still widely used in Linux socket filtering, seccomp filters and the packet-filtering paths of software such as Docker and Chrome.

The Linux fix clears stored branch predictions when a BPF program reuses a region an earlier one occupied. Oracle's GraalVM instead randomizes where its generated code is placed. The group says Mozilla considered a similar processor-level fix and is prioritizing site isolation in Firefox instead. They showed a browser proof of concept but say a full exploit would need further work.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Linux and Oracle Patch a New Spectre Flaw in Code Compiled on the Fly

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.