Branch Target Reuse lets an unprivileged Linux process read arbitrary host memory despite deployed Spectre-v2 defenses.
Public artifacts demonstrate the cross-privilege break end to end.
The Linux kernel cBPF JIT on x86 systems, demonstrated on stock Ubuntu 24.04.
Cross-privilege disclosure of arbitrary host memory from an unprivileged process
Deployed Spectre-v2 defenses no longer close this path: public artifacts demonstrate arbitrary host-memory recovery from an unprivileged process.
Detail, proof-of-concept code and 5 sources
An unprivileged process that can install cBPF filters trains the dispatcher, frees its JIT allocation and forces controlled address reuse; a stale indirect-branch prediction then enters newly generated code at an obsolete or misaligned offset.
The demonstrated chain recovers KASLR state, follows kernel aliases into arbitrary process memory and extracts a live su process's root password hash in an average of three to five minutes on the tested systems.
The upstream Linux mitigation issues an indirect branch prediction barrier when a JIT allocation is reused.
- access:local:unprivileged
- code running as an unprivileged local user
- interaction:none
- no user action required
- Reaches end-of-life hardware
- No
The first two questions are unknown because this is a runtime kernel hardening change, not a documented artifact-revocation fix.