New Spectre v2 attack variant leaks Linux root password hash in minutes

A New Variant of Spectre v2 Exploits Intel Computers Running Linux, Leaking Root Password Hashes in Minutes

A groundbreaking new attack variant has been discovered that can recover root password hashes from Intel computers running Linux in a matter of minutes. Dubbed Branch Target Reuse (BTR), this attack exploits a vulnerability in the way modern CPUs predict branch instructions, allowing an attacker to trick the processor into temporarily executing the wrong code and exposing sensitive data.

Developed by researchers at VUsec and Scuola Superiore Sant’Anna, BTR takes advantage of stale information stored in a CPU’s branch predictor after a just-in-time (JIT) engine reuses memory for new code. By manipulating this leftover information, an attacker can temporarily bypass the normal execution flow and access sensitive data, including root password hashes.

The researchers conducted extensive testing on various Linux systems, using unprivileged classic BPF programs to train the prediction, free the original program, and place a different program in the reused memory. This allowed them to trick the CPU into executing attacker-crafted instructions at a misaligned offset, causing data access during speculative execution and generating a measurable cache trace that revealed the data byte by byte.

In their experiments, the researchers were able to recover root password hashes from Linux systems running on both Raptor Cove and Lion Cove processors. Notably, they achieved this feat in just 3-5 minutes, demonstrating the practicality of BTR in real-world environments.

While leaking a password hash is not equivalent to retrieving it in plaintext, an attacker can still attempt to crack the hash offline or using cloud computing resources. The strength of the password and the hashing algorithm used will determine the success of such an attack. As a result, this new variant of Spectre v2 poses a significant threat to Linux systems, particularly those running on modern Intel processors.

The researchers have already notified affected vendors, who have assigned identifiers CVE-2026-64507 and CVE-2026-64508 to the issues. Fixes have been merged into the Linux kernel, but it’s essential for users to update their systems as soon as possible to mitigate this vulnerability.

In conclusion, BTR highlights the ongoing risks associated with Spectre v2 attacks, which were previously thought to be impractical due to self-modifying code (SMC) serving as a basis for dynamic code generation. This new variant demonstrates that SMC-based transient execution attacks can be used in real-world environments to expose sensitive data.

To protect yourself from this vulnerability, ensure your Linux system is running the latest kernel version and apply any available patches. Additionally, consider implementing additional security measures, such as using secure password hashing algorithms and regularly rotating passwords.


Source: Bleeping Computer — 2026-09-29