Судлаачид орчин үеийн CPU-ийн гүйцэтгэлийг сайжруулах зорилготой “таамаглалт гүйцэтгэл” (speculative execution) технологид суурилсан Spectre эмзэг байдлын шинэ хувилбарыг илрүүллээ.
Нидерландын Vrije Universiteit болон Италийн Scuola Superiore Sant’Anna-гийн судлаачид Сандер Вибинг, Юхуй Жу, Алессандро Бионди, Кристиано Жуффрида нар Branch Target Reuse (BTR) хэмээх шинэ төрлийн халдлагыг тодорхойлжээ. Энэхүү арга нь хөтөч болон системийн цөмд ашиглагддаг JIT (just-in-time) хөрвүүлэгчдэд нөлөөлдөг бөгөөд Linux cBPF, Oracle GraalVM, Mozilla SpiderMonkey зэрэг программ хангамжуудад аюул учруулж болзошгүй байна.
Судлаачдын тайлбарласнаар, орчин үеийн CPU-үүд өөрийгөө өөрчилсний дараа архитектурын уялдаа холбоог сэргээдэг ч хуучирсан салбарлалтын таамаглалын өгөгдлийг бүрэн устгадаггүй аж. Үүний улмаас халдагчид JIT хөдөлгүүрт үлдсэн кодын сул талыг ашиглан системийн нууцлагдсан өгөгдөл, тухайлбал нууц үгийн хэшийг олж авах боломжтой болж байна. Intel-ийн Raptor Cove болон Lion Cove процессор дээр хийсэн туршилтаар өгөгдөл алдагдлын хурд секундэд 5.4–5.7 КБ хүрэх боломжтойг тогтоожээ.
Энэхүү судалгааны үр дүнд CVE-2026-64507 болон CVE-2026-64508 гэсэн хоёр эмзэг байдлын дугаар олгогдсон байна. Linux цөмийн хөгжүүлэгчид болон Oracle компаниуд хамгаалалтын арга хэмжээ авсан бол Mozilla компани уг асуудлыг шууд шийдвэрлэхийн оронд сайтын тусгаарлалтын (site isolation) ажилд анхаарлаа хандуулахаар шийджээ.
Уг судалгааны ажлыг 2026 оны 11 дүгээр сарын 15-19-ний хооронд Нидерландын Гааг хотод болох ACM-ийн Компьютер болон харилцаа холбооны аюулгүй байдлын бага хурлаар (CCS 2026) хэлэлцүүлэхээр товлоод байна. IBPB зэрэг хамгаалалтын хүчтэй аргууд үр дүнтэй хэдий ч системийн гүйцэтгэлийг бууруулж, нарийн төвөгтэй байдлыг нэмэгдүүлдэг тул мэргэжилтнүүд анхааралтай хандахыг зөвлөж байна.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, runtimes, and kernels. The vulnerability is found in many CPUs that use speculative execution, the process of executing code before it is called to boost performance. Researchers found speculative execution opens the door to side channel attacks through which secrets can be exposed or inferred. When news of that risk became known, chipmakers and OS developers scrambled to fix these vulnerabilities, which were referred to as Spectre and Meltdown. And since then, researchers have found two or three dozen variations, such as 2025’s VMScape, one of several so-called “Spectre v2” attacks that attempt to exploit indirect branch prediction, where program control is passed indirectly by pointing to an address where the next instruction can be found rather than specifying the instruction itself. The attacker trains the branch predictor to execute speculatively to a chosen address in order to leak data about the microarchitecture state. Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have revived Spectre in a form called Branch Target Reuse (BTR), which they describe as the first practical in-place Spectre v2 attack that attacks just-in-time (JIT) compilers. An in-place attack is confined to the victim’s branch while an out-of-place attack relies on speculation directed toward a target on a different branch. The researchers – Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida – found that this novel Spectre form can be conjured from code left in JIT engines including Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey. “The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets),” the authors explain. “In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a speculative execute-after-free primitive.” The result is that an attacker can commandeer speculative control flow in a way that avoids some software defenses like FineIBT [PDF]. The authors showed they could exploit this flaw by designing two proof-of-concept exploits against an Intel-based Linux kernel that reveal the root password hash even with the constant binding defense provided by cBPF. The expected leakage rate is 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove. It’s slow but enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system. After the researchers disclosed their findings, Linux kernel developers and Oracle put mitigations in place. Two CVEs were assigned: CVE-2026-64507 and CVE-2026-64508. Mozilla, the researchers said, has opted to prioritize work on site isolation instead of addressing the issue directly. Strong mitigations like IBPB are said to be effective but add complexity and hinder performance. The Branch Target Reuse paper has been accepted for publication at the ACM Conference on Computer and Communications Security (CCS) 2026, which will be held November 15 through 19 in The Hague, Netherlands. ®

