New Spectre v2 attack variant leaks Linux root password hash within minutes

· CyberSecurity

TLDR

  • Researchers from VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), CVE-2026-64507 and CVE-2026-64508, a new Spectre v2 variant that survives self-modifying code protections in JIT engines that were assumed safe since 2018.
  • A working exploit against the Linux kernel's classic BPF JIT recovered a root password hash from a running su process's memory within three to five minutes on Intel systems.
  • The researchers confirmed the underlying stale branch-predictor behaviour on every CPU they tested, covering Intel, AMD and Arm, though the full end-to-end exploit was only completed against Linux.
  • Fixes have already been merged into the Linux kernel; GraalVM mitigates by randomising JIT code-cache locations, while Firefox is prioritising site isolation over an IBPB-based fix for now.

Researchers Sander Wiebing, Yuhui Zhu, Alessandro Biondi and Cristiano Giuffrida disclosed Branch Target Reuse (BTR), a Spectre v2 variant that exploits stale entries in a CPU's branch target buffer left behind when a JIT engine reuses memory for new code.1 An attacker allocates a "training chunk" to insert a branch-target-buffer entry, deallocates it, then reallocates a "target chunk" at the same address, tricking the CPU into speculatively executing the wrong instructions and disclosing secret data through a cache side-channel, which the researchers describe as "a transient execute-after-free primitive."1 The field had assumed since 2018 that self-modifying-code protections in JIT engines made such attacks impractical; BTR shows they remain exploitable in practice.1

The researchers tested SpiderMonkey (Firefox's JIT engine), Oracle's GraalVM, and the Linux kernel's classic BPF JIT.1 Only the Linux cBPF path produced a complete end-to-end exploit; SpiderMonkey showed stale predictions surviving without a full browser exploit, and GraalVM allowed a speculative sandbox-check skip that engine activity cleared before completion.2 Against Linux, the exploit recovered a root password hash from a running su process's memory at eight bytes per second, taking three minutes on Intel's Raptor Cove microarchitecture and five minutes on Lion Cove on average, and the exploit still succeeded within five minutes even against Linux's "constant blinding" hardening option.2 The researchers said they "confirmed this behaviour on every CPU we tested, covering Intel, AMD and Arm."2

Fixes tied to CVE-2026-64507 and CVE-2026-64508 have already been merged into the Linux kernel, and users are advised to apply the latest kernel and firmware updates.2 GraalVM mitigates by randomising JIT code-cache locations, and Mozilla is weighing IBPB-based mitigations for Firefox but is currently prioritising completion of its site isolation work instead.1

Why it matters: BTR overturns an eight-year-old assumption that self-modifying-code protections in JIT engines were enough to block this class of Spectre attack, and a root password hash recoverable in three to five minutes from unprivileged code is a meaningful escalation path on any unpatched Linux system running untrusted JIT-compiled code.

Sources

  1. New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses (The Hacker News)
  2. New Spectre v2 attack variant leaks Linux root password hash in minutes (BleepingComputer)