Skip to main content
Emerging ThreatsMalware & Ransomware

New Spectre v2 Variant Exploits Linux Systems, Leaks Root Password Hashes

Rows of computer servers and networking equipment in a dimly lit data center interior.
“We evaluated the end-to-end exploit on both Raptor Cove and Lion Cove, and leaked the password within 3 and 5 minutes on average, respectively,” the researchers claim.

What Branch Target Reuse (BTR) is and how it works

Branch Target Reuse (BTR) is a new variant of the Spectre v2 speculative-execution class of attacks identified by researchers at VUsec (the Systems and Network Security Group at VU Amsterdam) and Scuola Superiore Sant'Anna. BTR exploits stale state in a processor’s indirect-branch predictor after a just-in-time (JIT) engine frees and then reuses the same memory for new code. When the CPU retains an old indirect-branch prediction for an address whose contents have been replaced, it can speculatively execute the new code from the stale target, briefly running attacker-crafted instructions that would not execute under normal control flow.

How the attack was used to leak Linux root password hashes

In laboratory tests on Linux, the researchers used unprivileged classic BPF (cBPF) programs to train the branch predictor, free the original program, and place a different program in the same memory area. The stale prediction caused the CPU to speculatively execute the attacker-controlled instructions at a misaligned offset, producing measurable cache side effects. By observing those cache traces the team reconstructed memory contents byte by byte, at a measured rate of eight bytes per second, and located a running su process to recover the root password hash from its memory.

The paper describes two end-to-end exploits against Linux cBPF: one that works under default kernel configuration and a second that works when the kernel’s constant blinding hardening option is enabled. In the hardened case, the exploit encodes attacker-controlled instructions in jump offsets and still recovered the hash within five minutes, the researchers report.

Results across processors and JIT engines: SpiderMonkey and GraalVM

Although the headline test that recovered a root password hash was demonstrated on Intel hardware running Linux, the researchers said they “confirmed this behavior on every CPU we tested, covering Intel, AMD and Arm.” The team evaluated two separate JIT engines as part of their analysis: Firefox’s SpiderMonkey and Oracle’s GraalVM. In SpiderMonkey, VUsec’s proof-of-concept showed that stale branch predictions can survive code reuse, though that work did not demonstrate a complete browser exploit. In GraalVM the researchers identified a speculative path that could skip a sandbox check; in their experiments, however, normal engine activity cleared the stale predictions before a full exploit could complete.

Vulnerability identifiers, disclosure, and mitigations

The researchers notified affected vendors; the issues received identifiers CVE-2026-64507 and CVE-2026-64508. Fixes have already been merged into the Linux kernel. The published guidance is straightforward: users should apply available OS and firmware updates, and Linux users are advised to upgrade to the latest kernel version. VUsec also highlights a structural gap: “Indirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code,” the group wrote, adding, “No current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable.”

What this means for Linux users, JIT engine maintainers, and cloud defenders

  • Linux users and system administrators: apply the merged kernel fixes and firmware updates. Even though BTR recovers a password hash (not plaintext), an attacker can attempt offline cracking against that hash using cloud compute or other resources; success will depend on the hash algorithm and password strength.
  • JIT engine maintainers (Firefox SpiderMonkey, GraalVM teams): the proofs-of-concept show stale predictions can survive code reuse in real engines and can, in some cases, open speculative paths that bypass intended checks. Engine teams will need to evaluate their memory-reuse and code-generation strategies in light of BTR.
  • Cloud and enterprise defenders: the end-to-end cBPF exploits demonstrate that unprivileged code paths running on shared hardware can be used to leak sensitive kernel-memory data within minutes on tested platforms; defenders should prioritize patching and consider mitigations that reduce predictable memory reuse for JIT and dynamically generated code.

BTR reverses an assumption that has guided defenses since 2018 — that self-modifying-code-based transient-execution attacks were impractical against commodity JITs — showing instead that SMC-based speculative attacks can be practical in real-world environments. The researchers’ disclosure, the merged kernel fixes, and the broad confirmation of the behavior across CPU vendors frame a clear and narrow set of next steps: deploy updates and watch whether processor vendors introduce mechanisms to keep branch predictors and code state synchronized. Until that design-level change arrives, the researchers warn, modern CPUs remain susceptible to this class of attack.

Original story at BleepingComputer