New Spectre v2 attack variant leaks Linux root password hash in minutes
VUsec's Branch Target Reuse Spectre v2 variant leaks Linux root password hashes in minutes by abusing stale branch predictor entries after JIT code reuse.
Researchers at VU Amsterdam's VUsec and Scuola Superiore Sant'Anna developed Branch Target Reuse (BTR), which exploits stale branch predictor targets when JIT engines reuse freed code memory. An end-to-end exploit against Linux cBPF recovered the root password hash from a running 'su' process at eight bytes per second, taking 3-5 minutes on Intel Raptor Cove and Lion Cove CPUs. The issues received CVE-2026-64507 and CVE-2026-64508, with fixes already merged into the Linux kernel. The behavior was confirmed on Intel, AMD, and Arm CPUs, and a variant bypassed constant blinding hardening while still recovering the hash within five minutes.