New CPU Attack Steals Linux Root Password Hashes from Memory
Key Takeaways A new Spectre-v2 variant, Branch Target Reuse (BTR), has been discovered, enabling local attackers to steal sensitive data, including root password hashes, from Linux systems. The...
Key Takeaways
- A new Spectre-v2 variant, Branch Target Reuse (BTR), has been discovered, enabling local attackers to steal sensitive data, including root password hashes, from Linux systems.
- The attack exploits stale CPU branch-prediction data in Just-In-Time (JIT) compilers within the Linux kernel, web browsers, and language runtimes.
- Researchers demonstrated successful exploitation against the Linux kernel’s cBPF JIT, even bypassing existing mitigations, and identified Mozilla Firefox’s SpiderMonkey and Oracle’s GraalVM as vulnerable.
- Fixes for the Linux kernel are available under CVE-2026-64507 and CVE-2026-64508, which introduce an Indirect Branch Prediction Barrier (IBPB).
New CPU Attack Leaks Linux Root Password Hashes via Stale Branch Predictions
A novel variant of the notorious Spectre-v2 attack, dubbed Branch Target Reuse (BTR), has been unveiled, posing a significant threat to Linux systems. This sophisticated CPU-level side-channel attack exploits outdated branch-prediction data to covertly extract sensitive information from memory, including critical root password hashes.
Table Of Content
Targeting JIT Compilers
BTR specifically targets Just-In-Time (JIT) compilers, components frequently found within the Linux kernel, popular web browsers, and various language runtimes. The vulnerability stems from a fundamental mismatch that arises when code memory is repurposed, conflicting with the processor’s internal branch target buffer (BTB).
In modern CPU architectures, when a JIT engine reallocates memory—deleting old code and placing new code in the same address space—the processor’s branch prediction mechanisms may retain outdated indirect-branch predictions. An attacker can then manipulate these stale predictions to trigger speculative execution at a memory location that no longer contains the original code. This speculative execution leaves behind observable microarchitectural traces, such as changes in cache activity, even though the CPU ultimately discards the incorrect execution path.
Speculative Execute-After-Free in Action
By meticulously measuring these subtle side-channel effects, attackers can infer sensitive bytes from protected memory regions. This technique is aptly termed “speculative execute-after-free,” as it compels the CPU to follow a target associated with code that has been deallocated.

Researchers evaluating the BTR attack successfully developed proof-of-concept exploits against the Linux kernel’s classic Berkeley Packet Filter (cBPF) JIT compiler. They also identified Mozilla Firefox’s SpiderMonkey JavaScript engine and Oracle’s GraalVM as susceptible.
In a compelling demonstration against the Linux kernel, an unprivileged local process first “trained” an indirect branch to a specific JIT-generated cBPF code block. The attacker then orchestrated the removal of this code block and arranged for a different cBPF program to occupy a portion of the same JIT memory region. When the indirect branch was subsequently triggered, the CPU utilized the stale target prediction, leading to speculative execution of attacker-controlled bytes at a misaligned offset.
The research team successfully demonstrated the ability to leak arbitrary kernel memory at a rate of approximately 8 bytes per second on contemporary Intel processors. Most alarmingly, they navigated the Linux kernel task list, located a running su process, probed its memory, and successfully extracted the root password hash after it had been loaded into memory. VUSec testing showed that this critical hash could be recovered in an average of about three minutes on Raptor Cove systems and five minutes on Lion Cove systems.

Mitigation Challenges and Impact
A significant concern is that the BTR attack managed to bypass existing mitigations on the tested Linux configurations. However, it requires a local attacker to execute code and manipulate JIT-compiled cBPF programs, meaning it is not a direct remote network attack vector.
BTR poses a particular threat to JIT engines that frequently allocate, deallocate, and reuse executable memory. While the use of unprivileged eBPF has some restrictions, classic BPF remains widely deployed in critical areas such as seccomp filtering, socket filters, browser sandboxes, container environments, and packet-processing tasks. Even without full exploitation, SpiderMonkey was identified as vulnerable due to the potential for stale predictions to persist across code-cache reuse events.

What You Should Do
- Apply Kernel Patches: Linux kernel developers have released fixes for BTR, tracked as CVE-2026-64507 and CVE-2026-64508. These updates incorporate an Indirect Branch Prediction Barrier (IBPB) to clear stale indirect-branch predictions during BPF JIT memory reuse. Organizations should prioritize updating their Linux kernels immediately.
- Update Software: Ensure all deployments of Oracle GraalVM and web browsers like Mozilla Firefox are updated to their latest versions to incorporate any relevant security improvements.
- Minimize Untrusted Code: Restrict the ability of untrusted local code to execute on critical systems. Implement strict sandboxing for all workloads, particularly those involving JIT-compiled programs.
- Regular Patch Management: Maintain a robust patch management strategy to ensure timely application of all security updates across your infrastructure.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.