News

Spectre Attack Leaks Linux Root Password Hashes in Minutes Across Intel, AMD, and Arm CPUs

Branch Target Reuse, a new Spectre v2 variant, abuses stale branch predictions after JIT code reuse to leak a Linux root password hash in about three to five minutes.

Spectre Attack Leaks Linux Root Password Hashes in Minutes Across Intel, AMD, and Arm CPUs

Eight years after Spectre, CPUs still cannot forget where they used to jump. Researchers at VUSec (VU Amsterdam) and Scuola Superiore Sant'Anna have disclosed Branch Target Reuse, or BTR, a new Spectre v2 variant that leaked a Linux root password hash in minutes. They saw the underlying behavior on every Intel, AMD, and Arm processor they tested.

Execute after free, inside the CPU

The attack targets just-in-time compilers, the engines that generate machine code on the fly in browsers, language runtimes, and the kernel itself. JIT engines constantly free old code and write new code into the same memory addresses.

Modern CPUs handle that correctly at the architectural level. The new instructions are what officially runs. But the indirect branch predictor, the part of the chip that guesses where a jump will land, keeps its old entries. The researchers call the result a transient execute-after-free: for a brief speculative window, the processor can run freshly generated code at stale offsets that made sense only for the code that used to live there. Anything it touches can then be read out through cache side channels.

Three minutes to a root hash

The team evaluated three JIT engines: Firefox's SpiderMonkey, GraalVM, and the Linux kernel's classic BPF JIT. The kernel produced the headline result.

Their end-to-end Linux exploit pulled the root password hash out of a running su process at about eight bytes per second. That took an average of three minutes on Intel's Raptor Cove cores and five on Lion Cove. It worked even with constant blinding switched on, a hardening feature meant to make JIT-generated code harder to weaponize.

The browser and Java results were less complete. In SpiderMonkey, stale predictions survived code reuse, but the proof of concept did not become a full browser exploit. In GraalVM, the CPU could speculatively skip a sandbox check, yet other activity cleared the predictions before a working attack came together.

A leaked hash is also not a plaintext password. An attacker still has to crack it, and that depends on the hashing algorithm and how strong the password is. Still, reading root's credentials from an unprivileged position is exactly the kind of boundary violation Spectre mitigations were supposed to end.

The fix the hardware does not have

The flaws are tracked as CVE-2026-64507 and CVE-2026-64508, and Linux kernel fixes have already been merged. Those patches close the paths the researchers used. They do not fix the processor.

Cristiano Giuffrida of VUSec put the problem plainly: no current CPU keeps its branch predictor in sync with rewritten code, and until vendors build that in, this class of processors stays vulnerable. Every JIT engine is a candidate, and software teams will be patching around the gap one engine at a time.

For admins, the practical step is ordinary: install the latest kernel and any firmware or microcode updates as vendors ship them. It joins a busy month that already brought an Apple CoreGraphics zero-day and actively exploited Citrix NetScaler flaws, but BTR is different in kind. Those bugs live in code that can be rewritten. This one lives in silicon already sitting in data centers and laptops everywhere.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free