New Spectre v2 BTR Attack Can Steal Linux Root Password Hashes in Minutes
Researchers have discovered a new Spectre v2 attack variant called Branch Target Reuse (BTR) that can recover root password hashes from Intel systems running Linux within minutes.
BTR exploits stale information in a processor’s branch predictor after a just-in-time (JIT) engine reclaims memory previously used for code. By manipulating the leftover branch-prediction data, an attacker can make the CPU temporarily execute incorrect instructions and potentially leak sensitive information.
Researchers from VUSec, VU Amsterdam’s Systems and Network Security Group, and Scuola Superiore Sant’Anna developed the attack and evaluated its practicality against Firefox’s SpiderMonkey JavaScript engine, GraalVM, and the Linux kernel’s classic BPF (cBPF).
VUSec’s Cristiano Guiffrida told BleepingComputer that BTR is significant because researchers have generally considered this type of attack impractical since 2018. That assumption was based on the self-modifying code (SMC) used by general-purpose JIT engines to dynamically generate code.
BTR demonstrates that SMC-based temporary execution attacks can be practical in real-world environments and may be used to leak root password hashes.
The researchers notified affected vendors, and the issue has been assigned CVE-2026-64507 and CVE-2026-64508. A fix has already been merged into the Linux kernel.
How the Spectre v2 BTR attack works
Spectre v2 is a speculative-execution side-channel attack that tricks a CPU into briefly executing instructions at an incorrectly predicted jump destination. Information accessed during that speculative execution can then be inferred through CPU cache activity.
The BTR variant reuses old branch predictions after the destination code has been replaced, according to the researchers’ technical paper.
The attack targets the gap between JIT-compiled code and the processor’s branch predictor. When a JIT engine releases code and places new code at the same memory address, the CPU may still retain the indirect branch target associated with the old code.
When a later branch is executed, the processor may speculatively run the new code from the old target for a short time, even though normal execution would continue elsewhere.

Source: VUSec
BTR recovered a Linux root password hash in minutes
In their Linux tests, the researchers used an unprivileged classic BPF program to train the processor’s branch predictions. They then freed the original program and placed a different program in the reclaimed memory.
The stale branch target caused the CPU to execute attacker-controlled instructions at misaligned offsets. These instructions performed data accesses during speculative execution, producing measurable cache traces that allowed the researchers to infer data byte by byte.
The researchers identified the running su process and recovered the root password hash from its memory at a rate of 8 bytes per second.
“We evaluated end-to-end exploits on both Raptor Cove and Lion Cove, which compromised passwords on average within 3 and 5 minutes, respectively,” the researchers said.
Recovering a password hash is not the same as obtaining the password in clear text. However, an attacker can try to crack the hash using offline or cloud computing resources. The outcome depends on the hashing algorithm and the strength of the password.
The researchers published technical documentation describing two end-to-end exploits against Linux cBPF: one using the default settings and another with the Always Blind Enhancement option enabled.
In the latter scenario, the exploit encodes attacker-controlled instructions with a jump offset and still recovers the hash within five minutes.

Source: VUSec
Firefox and GraalVM JIT engines also examined
The researchers separately investigated Firefox’s SpiderMonkey and Oracle’s GraalVM JIT engines for potential BTR exposure.
In SpiderMonkey, the VUSec proof of concept demonstrated that old branch predictions survive code reuse, but the researchers did not complete a browser exploit.
In GraalVM, the researchers identified a way to speculatively bypass sandbox checks. However, activity within the engine cleared the stale predictions before the attack could be completed in their experiments.
Modern Intel, AMD and Arm CPUs may be affected
The researchers said that most modern hardware may be vulnerable to BTR.
“Indirect branch prediction is inherent in modern CPUs, and BTR takes advantage of the asynchrony between the branch predictor and the actual state of the code,” VUSec explained.
“Current CPUs do not have a mechanism to keep the two in sync, so until vendors add one, they will be vulnerable.”
“We observed this behavior on all CPUs tested, including Intel, AMD, and Arm.”
How to protect against the BTR attack
Users should install available operating system and firmware updates. Linux users are encouraged to upgrade to the latest kernel version, which includes the merged fix.
Previous VUSec research into speculative execution and CPU microarchitecture attacks includes RIDL, BHI, SLAM, and other attacks targeting modern processors.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



