Researchers at VUsec (VU Amsterdam) and Scuola Superiore Sant'Anna have developed the BTR attack, which leverages a gap between JIT-compiled code and the CPU's branch predictor. When a JIT engine frees code and puts new code at the same address, the CPU may still remember an indirect branch target from the old code. On a later branch, it can briefly execute the new code from that stale target speculatively, even though normal execution would go elsewhere.
In tests on Linux, the researchers used unprivileged classic BPF programs to train that prediction, free the original program, and place a different program in the reused memory. The stale target led the CPU to execute attacker-crafted instructions at a misaligned offset, causing data access during speculative execution and generating a measurable cache trace that allowed the researchers to infer data byte by byte. They located a running 'su' process and recovered the root password hash from its memory at a rate of eight bytes per second.
“We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively,” the researchers claim. VUSec's Cristiano Guiffrida told BleepingComputer that the attack remains an important finding, “considering that since 2018 the field assumed that these kinds of attacks were not practical due to self-modifying code (SMC) serving as the basis for dynamic code generation in commodity JIT engines.” BTR demonstrates the opposite, showing SMC-based transient execution attacks are practical in real-world environments.
The researchers notified affected vendors, and the issues received identifiers CVE-2026-64507 and CVE-2026-64508. Fixes have already been merged into the Linux kernel. From a practical standpoint, leaking a password hash is not the same as retrieving the password, but it significantly reduces the barrier for attackers.