Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ModSecurity Flaws Let Attackers Bypass WAF Protections
October 1, 2026
MetaMask Infrastructure Incident Exposes User IP Addresses
October 1, 2026
Critical PS5 Kernel Exploit Affects All Firmware Versions
October 1, 2026
Home/CyberSecurity News/New CPU Attack Steals Linux Root Password Hashes from Memory
CyberSecurity News

New CPU Attack Steals Linux Root Password Hashes from Memory

Key Takeaways A new Spectre-v2 variant, Branch Target Reuse (BTR), has been discovered, enabling local attackers to steal sensitive data, including root password hashes, from Linux systems. The...

Marcus Rodriguez
Marcus Rodriguez
October 1, 2026 4 Min Read
3 0

Key Takeaways

  • A new Spectre-v2 variant, Branch Target Reuse (BTR), has been discovered, enabling local attackers to steal sensitive data, including root password hashes, from Linux systems.
  • The attack exploits stale CPU branch-prediction data in Just-In-Time (JIT) compilers within the Linux kernel, web browsers, and language runtimes.
  • Researchers demonstrated successful exploitation against the Linux kernel’s cBPF JIT, even bypassing existing mitigations, and identified Mozilla Firefox’s SpiderMonkey and Oracle’s GraalVM as vulnerable.
  • Fixes for the Linux kernel are available under CVE-2026-64507 and CVE-2026-64508, which introduce an Indirect Branch Prediction Barrier (IBPB).

New CPU Attack Leaks Linux Root Password Hashes via Stale Branch Predictions

A novel variant of the notorious Spectre-v2 attack, dubbed Branch Target Reuse (BTR), has been unveiled, posing a significant threat to Linux systems. This sophisticated CPU-level side-channel attack exploits outdated branch-prediction data to covertly extract sensitive information from memory, including critical root password hashes.

Table Of Content

  • Key Takeaways
  • New CPU Attack Leaks Linux Root Password Hashes via Stale Branch Predictions
  • Targeting JIT Compilers
  • Speculative Execute-After-Free in Action
  • Mitigation Challenges and Impact
  • What You Should Do

Targeting JIT Compilers

BTR specifically targets Just-In-Time (JIT) compilers, components frequently found within the Linux kernel, popular web browsers, and various language runtimes. The vulnerability stems from a fundamental mismatch that arises when code memory is repurposed, conflicting with the processor’s internal branch target buffer (BTB).

In modern CPU architectures, when a JIT engine reallocates memory—deleting old code and placing new code in the same address space—the processor’s branch prediction mechanisms may retain outdated indirect-branch predictions. An attacker can then manipulate these stale predictions to trigger speculative execution at a memory location that no longer contains the original code. This speculative execution leaves behind observable microarchitectural traces, such as changes in cache activity, even though the CPU ultimately discards the incorrect execution path.

Speculative Execute-After-Free in Action

By meticulously measuring these subtle side-channel effects, attackers can infer sensitive bytes from protected memory regions. This technique is aptly termed “speculative execute-after-free,” as it compels the CPU to follow a target associated with code that has been deallocated.

BTR exploits stale BTB entries ( 1-5 ): Train, Jump, Free, Reuse, Leak(source : vusec )
BTR exploits stale BTB entries ( 1-5 ): Train, Jump, Free, Reuse, Leak (source: VUsec )

Researchers evaluating the BTR attack successfully developed proof-of-concept exploits against the Linux kernel’s classic Berkeley Packet Filter (cBPF) JIT compiler. They also identified Mozilla Firefox’s SpiderMonkey JavaScript engine and Oracle’s GraalVM as susceptible.

In a compelling demonstration against the Linux kernel, an unprivileged local process first “trained” an indirect branch to a specific JIT-generated cBPF code block. The attacker then orchestrated the removal of this code block and arranged for a different cBPF program to occupy a portion of the same JIT memory region. When the indirect branch was subsequently triggered, the CPU utilized the stale target prediction, leading to speculative execution of attacker-controlled bytes at a misaligned offset.

The research team successfully demonstrated the ability to leak arbitrary kernel memory at a rate of approximately 8 bytes per second on contemporary Intel processors. Most alarmingly, they navigated the Linux kernel task list, located a running su process, probed its memory, and successfully extracted the root password hash after it had been loaded into memory. VUSec testing showed that this critical hash could be recovered in an average of about three minutes on Raptor Cove systems and five minutes on Lion Cove systems.

BTR exploit with Linux kernel cBPF (source : vusec )
BTR exploit with Linux kernel cBPF (source: VUSec)

Mitigation Challenges and Impact

A significant concern is that the BTR attack managed to bypass existing mitigations on the tested Linux configurations. However, it requires a local attacker to execute code and manipulate JIT-compiled cBPF programs, meaning it is not a direct remote network attack vector.

BTR poses a particular threat to JIT engines that frequently allocate, deallocate, and reuse executable memory. While the use of unprivileged eBPF has some restrictions, classic BPF remains widely deployed in critical areas such as seccomp filtering, socket filters, browser sandboxes, container environments, and packet-processing tasks. Even without full exploitation, SpiderMonkey was identified as vulnerable due to the potential for stale predictions to persist across code-cache reuse events.

cBPF constant-blinding bypass via jump offsets (source : vusec
cBPF constant-blinding bypass via jump offsets (source: Vusec )

What You Should Do

  • Apply Kernel Patches: Linux kernel developers have released fixes for BTR, tracked as CVE-2026-64507 and CVE-2026-64508. These updates incorporate an Indirect Branch Prediction Barrier (IBPB) to clear stale indirect-branch predictions during BPF JIT memory reuse. Organizations should prioritize updating their Linux kernels immediately.
  • Update Software: Ensure all deployments of Oracle GraalVM and web browsers like Mozilla Firefox are updated to their latest versions to incorporate any relevant security improvements.
  • Minimize Untrusted Code: Restrict the ability of untrusted local code to execute on critical systems. Implement strict sandboxing for all workloads, particularly those involving JIT-compiled programs.
  • Regular Patch Management: Maintain a robust patch management strategy to ensure timely application of all security updates across your infrastructure.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical MikroTik RouterOS Flaw (CVE-2023-30799) Allows Code Execution

Next Post

Critical PS5 Kernel Exploit Affects All Firmware Versions

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
GitHub Credentials Exposed: 543K Active Tokens Still Vulnerable
October 1, 2026
2CLoader Malware Evades Detection to Deploy Vidar and Remus Stealers
October 1, 2026
Critical TeamViewer Flaws Allow Remote Code Execution
October 1, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us