Researchers Use New CPU Attack to Steal Linux Root Password Hash From Memory
Researchers' Branch Target Reuse attack leaks Linux root password hashes via stale CPU predictions.
VUSec researchers disclosed Branch Target Reuse, a Spectre-v2 variant that abuses stale branch-target buffer entries after JIT code is freed and its memory is reused. Proof-of-concept exploits against the Linux kernel cBPF JIT leaked arbitrary kernel memory at about 8 bytes per second and recovered a root password hash from an su process in roughly three minutes on Raptor Cove and five minutes on Lion Cove Intel CPUs. The local attack worked despite cBPF constant blinding and is not a remote network exploit. Linux fixes tracked as CVE-2026-64507 and CVE-2026-64508 insert an Indirect Branch Prediction Barrier when BPF JIT memory is reused.
- Branch Target Reuse abuses stale branch-target buffer entries after JIT code is freed.
- Linux cBPF proofs leaked kernel memory at about 8 bytes per second.
- Root password hashes were recovered in about three to five minutes on Intel CPUs.
- CVE-2026-64507 and CVE-2026-64508 add an IBPB during BPF JIT memory reuse.
- The attack requires local code and is not a remote network exploit.
Vulnerabilities mentionedAll →
- CVE-2026-64507—<1%Linux kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2…published · Linux kernel+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-64507+1 related CVE | Linux kernel: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2… In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Enable IBPB flush on BPF JIT allocation Enable hardening against JIT spraying when Spectre-v2 mitigations are in use. Specifically, issue an IBPB flush on BPF JIT memory reuse. Skip enabling the IBPB flush if the BPF dispatcher is already using a retpoline sequence. This hardening applies only when BPF-JIT is in use. Guard the enabling under CONFIG_BPF_JIT so that bugs.c still builds with CONFIG_BPF_JIT=n. |
Full article623 words · extracted from cybersecuritynews.com · click to collapse
Branch Target Reuse (BTR) is a newly disclosed variant of the Spectre-v2 attack that leverages stale CPU branch-prediction data to leak sensitive information from Linux memory, including root password hashes.
This attack specifically targets just-in-time (JIT) compilers found in the Linux kernel, web browsers, and various language runtimes.
BTR takes advantage of a vulnerability that arises when code memory is reused, leading to a mismatch with the processor’s branch target buffer.
When a JIT engine deletes previously generated code and later allocates different code to the same memory space, modern CPUs may still hold onto old indirect-branch predictions.
An attacker can exploit stale predictions to trigger speculative execution at an outdated location, leaving observable microarchitectural traces such as cache activity even after the CPU discards the incorrect path.
New CPU Attack Steals Linux Root Password Hashes
By measuring these effects, attackers can infer sensitive bytes from protected memory through side-channel methods. This technique is referred to as speculative execute-after-free, as it allows the CPU to follow a target associated with code that no longer exists.
In their evaluations of the BTR attack, researchers tested it against Linux’s classic Berkeley Packet Filter (cBPF), Mozilla Firefox’s SpiderMonkey JavaScript engine, and Oracle’s GraalVM.
They successfully developed two proof-of-concept exploits against the Linux kernel’s cBPF JIT compiler, including an exploit that functioned even with cBPF constant blinding in place.
In the Linux demonstration, an unprivileged local process first trained an indirect branch to a JIT-generated cBPF code block. The attacker then removed that code block and arranged for a different cBPF program to reuse part of the same JIT memory region.
When the indirect branch was triggered again, the CPU used the stale target prediction and speculatively executed attacker-controlled bytes at a misaligned offset.
The researchers demonstrated that they could leak arbitrary kernel memory at a rate of about 8 bytes per second on modern Intel processors.
Notably, they walked through the Linux kernel task list, identified a running su process, inspected its memory, and successfully extracted the root password hash after it had been loaded into memory.
VUSec testing showed that the hash could be recovered in an average of about three minutes on Raptor Cove systems and five minutes on Lion Cove systems.

This attack is particularly concerning because it managed to bypass enabled mitigations on the Linux configurations tested. However, it does necessitate that the attacker run local code and manipulate JIT-compiled cBPF programs, meaning it is not a direct remote network attack.
BTR is significant for JIT engines that frequently allocate, free, and reuse executable memory. While unprivileged eBPF usage is limited, classic BPF remains in use for seccomp filtering, socket filters, browser sandboxes, containers, and packet-processing tasks.
SpiderMonkey, although not exploited in full, was also identified as being susceptible due to the potential for stale predictions to persist across code-cache reuse.

To mitigate the risks posed by this attack, Linux kernel developers have issued fixes tracked as CVE-2026-64507 and CVE-2026-64508.
These updates include an Indirect Branch Prediction Barrier (IBPB) to clear stale indirect-branch predictions during BPF JIT memory reuse.
Organizations should update their kernel, GraalVM deployments, and browser versions to improve security. Additionally, minimizing untrusted local code execution, sandboxing workloads, and implementing timely kernel patches are crucial defensive measures.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.