Researchers Discover Spectre Variant Capable of Leaking Linux Root Password Hashes
Share
A new variant of the Spectre v2 speculative execution attack, known as Branch Target Reuse (BTR), can recover root password hashes from Linux systems running on Intel hardware in as little as three to five minutes.
The discovery, made by researchers at VUsec (the Systems and Network Security Group at VU Amsterdam) and Scuola Superiore Sant’Anna, demonstrates that speculative execution attacks remain practical in real-world environments, even when involving self-modifying code (SMC).
How the BTR Attack Works
The BTR attack exploits a desynchronisation between a processor’s branch predictor and the actual state of the code being executed. This occurs specifically when a just-in-time (JIT) engine frees a block of code and subsequently reuses that same memory address for new code.
Because the CPU’s branch predictor may still retain stale information from the previous code at that address, an attacker can trick the processor into speculatively executing incorrect instructions. By observing the resulting cache traces, researchers were able to infer sensitive data byte by byte.
In experimental tests on Linux, the team used unprivileged classic Berkeley Packet Filter (cBPF) programs to train the prediction and recover root password hashes from the memory of a running ‘su’ process at a rate of eight bytes per second.
Affected Hardware and Software
The researchers evaluated the end-to-end exploit on Raptor Cove and Lion Cove architectures, reporting that password hashes were leaked within three and five minutes, respectively. While the primary demonstration focused on Intel, the team confirmed that this behaviour is inherent to modern CPUs, including those from AMD and Arm.
The attack also impacts various JIT engines used in common software. In Firefox’s SpiderMonkey engine, proof-of-concept tests showed that stale predictions survive code reuse. In Oracle’s GraalVM, researchers identified a method to speculatively bypass sandbox checks, though the engine’s activity cleared predictions before a full attack could be completed in their specific experiments.
Mitigation and Patching
The vulnerabilities have been assigned the identifiers CVE-2026-64507 and CVE-2026-64508. Fixes for these flaws have already been merged into the Linux kernel.
To mitigate the risk, Linux users are advised to upgrade to the latest kernel version immediately. Additionally, all users should apply the most recent operating system and firmware updates to ensure protection against these speculative execution vulnerabilities.




Leave a Reply