New Spectre v2 attack variant can leak Linux root password hash in minutes

Researchers demonstrate Branch Target Reuse (BTR) attack on Intel systems, prompting kernel fixes

By LineZotpaper
Published
Read Time2 min
A new variant of the Spectre v2 vulnerability, dubbed Branch Target Reuse (BTR), can recover root password hashes from Intel computers running Linux in just a few minutes, according to researchers. The attack exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code, making a class of attacks previously thought impractical a real-world threat.

Researchers at VUsec (VU Amsterdam) and Scuola Superiore Sant'Anna have developed the BTR attack, which leverages a gap between JIT-compiled code and the CPU's branch predictor. When a JIT engine frees code and puts new code at the same address, the CPU may still remember an indirect branch target from the old code. On a later branch, it can briefly execute the new code from that stale target speculatively, even though normal execution would go elsewhere.

In tests on Linux, the researchers used unprivileged classic BPF programs to train that prediction, free the original program, and place a different program in the reused memory. The stale target led the CPU to execute attacker-crafted instructions at a misaligned offset, causing data access during speculative execution and generating a measurable cache trace that allowed the researchers to infer data byte by byte. They located a running 'su' process and recovered the root password hash from its memory at a rate of eight bytes per second.

“We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively,” the researchers claim. VUSec's Cristiano Guiffrida told BleepingComputer that the attack remains an important finding, “considering that since 2018 the field assumed that these kinds of attacks were not practical due to self-modifying code (SMC) serving as the basis for dynamic code generation in commodity JIT engines.” BTR demonstrates the opposite, showing SMC-based transient execution attacks are practical in real-world environments.

The researchers notified affected vendors, and the issues received identifiers CVE-2026-64507 and CVE-2026-64508. Fixes have already been merged into the Linux kernel. From a practical standpoint, leaking a password hash is not the same as retrieving the password, but it significantly reduces the barrier for attackers.

§

Analysis

Why This Matters

  • This attack demonstrates that speculative execution vulnerabilities remain a live threat years after Spectre was disclosed, with practical exploitation possible on current hardware.
  • It undermines the long-held assumption that self-modifying code (SMC) in JIT engines prevents transient execution attacks, opening new avenues for data theft.
  • The ability to leak a root password hash in minutes could allow attackers with unprivileged access to escalate privileges on vulnerable Linux systems.

Background

Spectre v2 is a speculative execution side-channel attack disclosed in 2018 that tricks a CPU into temporarily executing instructions at a wrongly predicted jump destination, exposing data through cache timing. The BTR variant refines this by reusing old branch predictions after code at the target address has been replaced. The attack targets Intel processors with Raptor Cove and Lion Cove cores, using unprivileged classic BPF programs in the Linux kernel as an attack vector. Patches have already been merged into the Linux kernel.

Key Perspectives

Researchers (VUsec and Scuola Superiore Sant'Anna): They argue the attack is a significant finding because it shows SMC-based transient execution attacks are practical despite earlier assumptions to the contrary. Their end-to-end exploit achieved root hash leakage on Intel systems. Vendors (Intel, Linux kernel maintainers): The affected vendors were notified, and fixes have been incorporated into the Linux kernel. Further microcode or architectural mitigations may be required. Critics/Skeptics: Leaking a hash does not break the password directly, but it greatly reduces the work factor for offline cracking. The attack requires unprivileged access to run BPF programs, which may limit exploitability in locked-down environments. However, many Linux systems allow such access by default.

What to Watch

  • Adoption of kernel fixes by Linux distributions and cloud providers to mitigate the vulnerability.
  • Potential microcode updates or hardware changes from Intel for future processor generations.
  • Proof-of-concept exploit code or real-world attempts by threat actors to weaponize BTR.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.