A newly discovered variant of the Spectre v2 attack, dubbed Branch Target Reuse (BTR), can steal Linux root password hashes from Intel computers in just a few minutes. This vulnerability affects not only high-security systems but also everyday users who rely on Linux-based operating systems.
Researchers at VUsec and Scuola Superiore Sant’Anna discovered the new Spectre v2 attack variant, which exploits a gap between JIT-compiled code and the CPU’s branch predictor. When a Just-In-Time (JIT) engine reuses memory for new code, it can leave behind stale information in the processor’s branch predictor. An attacker can manipulate this leftover information to trick the processor into executing wrong instructions temporarily, potentially exposing sensitive data.
The BTR attack works by reusing an old prediction after the code at that destination has been replaced. The researchers explain that the CPU may still remember an indirect branch target from the old code, which can lead to a brief execution of new code from that stale target speculatively. This allows attackers to train predictions, free original programs, and place different programs in reused memory, leading to data access during speculative execution.
In their experiments on Linux, the researchers used unprivileged classic BPF programs to leak root password hashes at a rate of eight bytes per second. They claim that they were able to recover the password hash within 3 and 5 minutes on average using Raptor Cove and Lion Cove processors, respectively.
This attack is significant because it demonstrates that self-modifying code-based transient execution attacks are practical in real-world environments. This goes against previous assumptions made since 2018, which considered such attacks impractical due to dynamic code generation in commodity JIT engines.
The researchers have already notified affected vendors, and fixes have been merged into the Linux kernel with identifiers CVE-2026-64507 and CVE-2026-64508. However, this vulnerability is not unique to Linux; most modern hardware is vulnerable to this new BTR attack due to its inherent nature in indirect branch prediction.
While leaking a password hash is not the same as retrieving it in plaintext, an attacker can attempt to crack the hash offline or using cloud computing resources. The strength of the password and hashing algorithm will play a significant role in determining success.
To put this into perspective, the Spectre v2 attack variant has shown that even modern hardware with advanced security features is not immune to such attacks. Until vendors add mechanisms to keep branch predictors in sync with code states, CPUs will remain vulnerable to BTR attacks.
In conclusion, users who rely on Linux-based operating systems should take note of this vulnerability and consider implementing additional security measures to protect their sensitive data. While fixes are already available for the affected kernel versions, it’s essential for users to stay vigilant and keep their systems up-to-date to prevent potential exploitation of this newly discovered Spectre v2 attack variant.
Source: Bleeping Computer — 2026-09-29