Download Privacy Needle App

Type to search

Cybersecurity

Researchers Discover Spectre Variant Capable of Leaking Linux Root Password Hashes

Share

A new variant of the Spectre v2 speculative execution attack, known as Branch Target Reuse (BTR), can recover root password hashes from Linux systems running on Intel hardware in as little as three to five minutes.

The discovery, made by researchers at VUsec (the Systems and Network Security Group at VU Amsterdam) and Scuola Superiore Sant’Anna, demonstrates that speculative execution attacks remain practical in real-world environments, even when involving self-modifying code (SMC).

How the BTR Attack Works

The BTR attack exploits a desynchronisation between a processor’s branch predictor and the actual state of the code being executed. This occurs specifically when a just-in-time (JIT) engine frees a block of code and subsequently reuses that same memory address for new code.

Because the CPU’s branch predictor may still retain stale information from the previous code at that address, an attacker can trick the processor into speculatively executing incorrect instructions. By observing the resulting cache traces, researchers were able to infer sensitive data byte by byte.

In experimental tests on Linux, the team used unprivileged classic Berkeley Packet Filter (cBPF) programs to train the prediction and recover root password hashes from the memory of a running ‘su’ process at a rate of eight bytes per second.

Affected Hardware and Software

The researchers evaluated the end-to-end exploit on Raptor Cove and Lion Cove architectures, reporting that password hashes were leaked within three and five minutes, respectively. While the primary demonstration focused on Intel, the team confirmed that this behaviour is inherent to modern CPUs, including those from AMD and Arm.

The attack also impacts various JIT engines used in common software. In Firefox’s SpiderMonkey engine, proof-of-concept tests showed that stale predictions survive code reuse. In Oracle’s GraalVM, researchers identified a method to speculatively bypass sandbox checks, though the engine’s activity cleared predictions before a full attack could be completed in their specific experiments.

Mitigation and Patching

The vulnerabilities have been assigned the identifiers CVE-2026-64507 and CVE-2026-64508. Fixes for these flaws have already been merged into the Linux kernel.

To mitigate the risk, Linux users are advised to upgrade to the latest kernel version immediately. Additionally, all users should apply the most recent operating system and firmware updates to ensure protection against these speculative execution vulnerabilities.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.