Spectre 微架构漏洞再次卷土重来,这一次困扰的是为浏览器、运行时和内核生成机器代码的即时编译(JIT)引擎。该漏洞存在于许多使用投机执行的 CPU 中,投机执行是在代码被调用前预先执行以提升性能的过程。研究人员发现,投机执行为侧信道攻击敞开了大门,通过此类攻击可以泄露或推断秘密信息。当这一风险被公之于众后,芯片制造商和操作系统开发商争相修复这些漏洞,它们被称为 Spectre(幽灵)和 Meltdown(熔断)。
The Spectre microarchitecture vulnerability has returned yet again, this time to vex just-in-time (JIT) engines that generate machine code for browsers, runtimes, and kernels. The vulnerability is found in many CPUs that use speculative execution, the process of executing code before it is called to boost performance. Researchers found speculative execution opens the door to side channel attacks through which secrets can be exposed or inferred. When news of that risk became known, chipmakers and OS developers scrambled to fix these vulnerabilities, which were referred to as Spectre and Meltdown.
从那时起,研究人员已发现二十到三十种变体,例如 2025 年的 VMScape,它是几种所谓的“Spectre v2”攻击之一,试图利用间接分支预测,即程序控制通过指向下一条指令所在的地址间接传递,而非直接指定指令本身。攻击者训练分支预测器投机性地执行到选定地址,以泄露关于微架构状态的数据。来自荷兰 Vrije 大学和意大利 Scuola Superiore Sant'Anna 的研究人员以分支目标复用(BTR)的形式重现了 Spectre,他们将其描述为首个针对即时(JIT)编译器的实用原位 Spectre v2 攻击。
And since then, researchers have found two or three dozen variations, such as 2025's VMScape, one of several so-called "Spectre v2" attacks that attempt to exploit indirect branch prediction, where program control is passed indirectly by pointing to an address where the next instruction can be found rather than specifying the instruction itself. The attacker trains the branch predictor to execute speculatively to a chosen address in order to leak data about the microarchitecture state. Researchers from Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy have revived Spectre in a form called Branch Target Reuse (BTR), which they describe as the first practical in-place Spectre v2 attack that attacks just-in-time (JIT) compilers.
原位攻击局限于受害者的分支,而异位攻击则依赖于指向不同分支上目标的投机执行。研究人员——Sander Wiebing、Yuhui Zhu、Alessandro Biondi 和 Cristiano Giuffrida——发现,这种新型 Spectre 形式可从 JIT 引擎中遗留的代码中触发,包括 Linux cBPF、Oracle GraalVM 和 Mozilla SpiderMonkey。“攻击的关键洞察在于,虽然现代 CPU 在自我修改后会恢复架构代码一致性,但它们不一定会使陈旧的间接分支预测条目(即分支目标)失效,”作者解释道。
An in-place attack is confined to the victim's branch while an out-of-place attack relies on speculation directed toward a target on a different branch. The researchers – Sander Wiebing, Yuhui Zhu, Alessandro Biondi, and Cristiano Giuffrida – found that this novel Spectre form can be conjured from code left in JIT engines including Linux cBPF, Oracle GraalVM, and Mozilla SpiderMonkey. "The key insight behind the attack is that, while modern CPUs restore architectural code coherence after self-modification, they do not necessarily invalidate stale indirect branch prediction entries (i.e., branch targets)," the authors explain.
在 JIT 引擎中,这些过时的目标可能比原始代码存活得更久,并在代码缓存重新填充时被重用,从而产生一种推测性释放后执行原语。结果是攻击者可以以一种避开某些软件防御(如 FineIBT [PDF])的方式劫持推测性控制流。作者展示了他们如何通过设计两个针对基于 Intel 的 Linux 内核的概念验证漏洞利用来利用此缺陷,即使在 cBPF 提供的常量绑定防御下,也能泄露 root 密码哈希。
"In JIT engines, these stale targets can outlive the original code and later be reused when the code cache is repopulated, yielding a speculative execute-after-free primitive." The result is that an attacker can commandeer speculative control flow in a way that avoids some software defenses like FineIBT [PDF]. The authors showed they could exploit this flaw by designing two proof-of-concept exploits against an Intel-based Linux kernel that reveal the root password hash even with the constant binding defense provided by cBPF.
预期泄露率为 Intel Raptor Cove 芯片 5.7 KB/秒,Lion Cove 为 5.4 KB/秒。速度虽慢,但足以让非特权用户从易受攻击的系统中窃取敏感的密码哈希。
The expected leakage rate is 5.7 KB/sec for Intel Raptor Cove chips and 5.4 KB/sec for Lion Cove. It's slow but enough for an unprivileged user to coax a sensitive password hash out of a vulnerable system.
研究人员披露发现后,Linux 内核开发人员和 Oracle 已部署缓解措施。分配了两个 CVE 编号:CVE-2026-64507 和 CVE-2026-64508。研究人员表示,Mozilla 选择优先推进站点隔离工作,而非直接解决该问题。据称,IBPB 等强力缓解措施虽有效,但会增加复杂性并损害性能。
After the researchers disclosed their findings, Linux kernel developers and Oracle put mitigations in place. Two CVEs were assigned: CVE-2026-64507 and CVE-2026-64508. Mozilla, the researchers said, has opted to prioritize work on site isolation instead of addressing the issue directly. Strong mitigations like IBPB are said to be effective but add complexity and hinder performance.
《分支目标重用》论文已被 ACM 计算机与通信安全会议 (CCS) 2026 接收,该会议将于 11 月 15 日至 19 日在荷兰海牙举行。®
The Branch Target Reuse paper has been accepted for publication at the ACM Conference on Computer and Communications Security (CCS) 2026, which will be held November 15 through 19 in The Hague, Netherlands. ®