Researchers disclose Spectre v2 variant 'BTR' that steals Linux root password hashes
Security researchers at VUsec and Scuola Superiore Sant'Anna developed a new Spectre v2 attack called Branch Target Reuse (BTR), which exploits stale branch predictor data left behind when JIT engines reuse memory addresses for new code. Tested against Firefox's SpiderMonkey, GraalVM, and the Linux kernel's cBPF, the attack can extract a system's root password hash within minutes on Intel processors. The flaws were assigned CVE-2026-64507 and CVE-2026-64508, and fixes have already been merged into the Linux kernel.
GoKawiil's interpretation of the reporting above, not reported fact.
The finding challenges an assumption held since 2018 that self-modifying code used in JIT engines made such transient-execution attacks impractical, according to VUsec's Cristiano Giuffrida. This suggests browsers, virtual machines, and kernel components relying on JIT compilation may need renewed scrutiny for speculative execution vulnerabilities. Because patches are already merging into the Linux kernel, the practical risk to unpatched systems could shrink quickly, though other affected JIT-based software may still need updates.
- BTR is a new Spectre v2 variant exploiting stale branch predictor entries after JIT code reuse.
- It can recover root password hashes on Intel-based Linux systems in minutes.
- Two CVEs were assigned and Linux kernel fixes have already been merged.
Source: bleepingcomputer.com, 2026-09-29
Published there as: “New Spectre v2 attack variant leaks Linux root password hash in minutes”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.