Linux and Oracle Patch a New Spectre Flaw in Code Compiled on the Fly

Researchers at the VUSec group at VU Amsterdam and at Scuola Superiore Sant'Anna disclosed a new variant of the Spectre-v2 processor attack on Sept. 29, 2026. Fixes have already shipped for the Linux kernel, where they are tracked as CVE-2026-64507 and CVE-2026-64508, and for Oracle's GraalVM runtime.
The flaw sits in just-in-time compilers, the components that build machine code while a program is running. The researchers' advice to system owners is to update the operating system and other software as soon as vendor patches are available; the Linux kernel and Oracle have released theirs.
The group calls the attack Branch Target Reuse. Modern processors remember where an indirect branch last jumped. The researchers found that the record can outlive the code it belonged to: after a just-in-time engine discards a block of generated code and places different code at the same address, the old prediction can still be used. They analyzed the Linux kernel's classic BPF filters, Oracle's GraalVM and Firefox's SpiderMonkey engine. They built two working exploits against the Linux kernel, one of which, they report, reads memory at 8 bytes a second on current Intel processors.
The researchers say they confirmed the underlying behavior on every processor they tested, covering Intel, AMD and Arm. The hardware vendors told the researchers that mechanisms to blunt this class of attack already exist and that mitigations for this variant belong in software. The group notes that classic BPF remains available to unprivileged programs and is still widely used in Linux socket filtering, seccomp filters and the packet-filtering paths of software such as Docker and Chrome.
The Linux fix clears stored branch predictions when a BPF program reuses a region an earlier one occupied. Oracle's GraalVM instead randomizes where its generated code is placed. The group says Mozilla considered a similar processor-level fix and is prioritizing site isolation in Firefox instead. They showed a browser proof of concept but say a full exploit would need further work.
