New Spectre v2 attack variant leaks Linux root password hash in minutes

by · BleepingComputer

A new Spectre v2 attack variant called Branch Target Reuse (BTR) can recover root password hashes from Intel computers running Linux in just a few minutes.

A BTR attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code.

By manipulating this leftover information, an attacker can trick the processor into temporarily executing the wrong instructions and potentially expose sensitive data.

Researchers at VUsec (Systems and Network Security Group at VU Amsterdam) and Scuola Superiore Sant'Anna devised the new attack and evaluated how practical it is against Firefox's JavaScript engine SpiderMonkey, GraalVM, and the Linux kernel's cBPF.

VUSec’s Cristiano Guiffrida explained to BleepingComputer that this attack remains an important finding, considering that since 2018 the field assumed that these kinds of attacks were not practical due to self-modifying code (SMC) serving as the basis for dynamic code generation in commodity JIT engines.

BTR demonstrates the opposite, showing that SMC-based transient execution attacks are practical in real-world environments and can be used to leak the hash for the root password.

The researchers notified the affected vendors, and the issues received the identifiers CVE-2026-64507 and CVE-2026-64508. Fixes have already been merged into the Linux kernel.

BTR leaks root password hash

In the Spectre-v2 speculative execution side-channel attack, the CPU is tricked into briefly running instructions at a wrongly predicted jump destination, which can expose data through the CPU cache.

Its BTR variant does this by reusing an old prediction after the code at that destination has been replaced, the researchers explain in a technical paper.

The new attack exploits a gap between JIT-compiled code and the CPU’s branch predictor; specifically, when a JIT engine frees code and puts new code at the same address, the CPU may still remember an indirect branch target from the old code.

On a later branch, a point where the CPU decides which instruction to run next, it can briefly execute the new code from that stale target speculatively, even though normal execution would go elsewhere.

BTR attack overview
Source: VUSec

In their tests on Linux, the researchers used unprivileged classic BPF programs to train that prediction, free the original program, and place a different program in the reused memory.

The stale target led the CPU to execute attacker-crafted instructions at a misaligned offset, causing data access during speculative execution and generating a measurable cache trace that let the researchers infer the data byte by byte.

Next, they located a running ‘su’ process and recovered the root password hash from its memory at a rate of eight bytes per second.

“We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively,” the researchers claim.

From a practical standpoint, leaking a password hash is not the same as retrieving the password in plaintext. However, an attacker can attempt to crack the hash offline or using cloud computing resources, with success depending on the hashing algorithm and the strength of the password.

The published technical paper demonstrates two end-to-end exploits against Linux cBPF: one at default configuration and one with the constant blinding hardening option enabled.

In the latter, the exploit is adapted to encode attacker-controlled instructions in jump offsets and still recover the hash within five minutes.

Exploit adapted to constant blinding hardening
Source: VUSec

The researchers also examined Firefox’s SpiderMonkey and Oracle’s GraalVM as separate JIT engines for BTR exposure.

In SpiderMonkey, VUSec’s proof-of-concept showed that stale predictions survive code reuse, but not a complete browser exploit.

In GraalVM, the researchers identified a way to speculatively skip a sandbox check, but the engine’s activity cleared the predictions before they could complete an attack in their experiments.

Regarding the real-world image, the researchers note that most modern hardware is vulnerable to this new BTR attack.

“Indirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code,” explained VUSec.

“No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable.”

“We confirmed this behavior on every CPU we tested, covering Intel, AMD and Arm.”

Users are recommended to apply OS and firmware updates, and Linux users are advised to upgrade to the latest kernel version.

Previous VUsec research on speculative execution and CPU microarchitectural attacks includes RIDL, BHI, SLAM, and other attacks targeting modern processors.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat