Cybersecurity

New Spectre v2 Variant Extracts the root Password Hash from Linux Systems in Minutes

Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed a Branch Target Reuse attack that exploits remnants of processor predictions after memory reuse in JIT engines, enabling them to extract the root password hash from Linux within 3 to 5 minutes in tests on Intel processors.

2026-09-29
4 min read
86 views
certi.news Editorial Team
New Spectre v2 Variant Extracts the root Password Hash from Linux Systems in Minutes

Researchers from VUSec, part of the Systems and Network Security Group at Vrije Universiteit Amsterdam, and Scuola Superiore Sant’Anna have disclosed a new variant of Spectre v2 attacks that they call Branch Target Reuse, or BTR. The attack exploits stale information retained by the processor’s branch predictor after memory is reused to run new code, enabling speculative instruction execution and the leakage of sensitive data.

In tests on Linux, the researchers recovered the root user’s password hash from the memory of a su process at a rate of eight bytes per second. Extracting the entire hash took an average of about three minutes on Raptor Cove processors and five minutes on Lion Cove processors, according to the researchers’ results.

How Does Branch Target Reuse Work?

The attack relies on a gap between code generated by just-in-time JIT engines and the state retained by the processor’s branch predictor. When JIT engines free code and place other code at the same address, the processor may retain an old prediction for the target of an indirect branch. When a subsequent branch is executed, the processor can temporarily run instructions from the old target, even though the correct execution path is different.

The researchers exploited this mechanism using unprivileged classic BPF programs to train the predictor, then freed the original program and placed another program in the reused memory. Speculative execution at a misaligned offset created measurable traces in the cache, enabling the researchers to infer the data byte by byte.

Scope of Impact and Practical Results

The team tested the attack on Linux cBPF in two configurations: the default configuration and a configuration that included the constant blinding hardening option. Even with the hardening, the exploit was modified to encode attacker-controlled instructions within branch offsets while retaining the ability to recover the hash in about five minutes.

The researchers also studied the susceptibility of Firefox SpiderMonkey and Oracle GraalVM. A proof of concept in SpiderMonkey demonstrated that old predictions persisted after code reuse, but it was not developed into a full browser exploit. In GraalVM, the researchers found a way to bypass the sandbox check speculatively, but engine activity erased the predictions before the attack could be completed in their experiments.

The researchers confirmed the behavior on all the processors they tested, including Intel, AMD, and Arm, noting that most modern hardware may be vulnerable. This is related to the absence of a current mechanism that guarantees synchronization between the branch predictor and the code’s actual state.

What Should System Administrators Do?

The researchers notified the affected parties, and the issues were assigned the identifiers CVE-2026-64507 and CVE-2026-64508. Fixes have been integrated into the Linux kernel, so the immediate step for Linux users is to upgrade to the latest available kernel version, along with applying operating system and firmware updates.

Stealing the hash does not mean directly recovering the plaintext password; the success of cracking it offline or using cloud computing resources depends on the hashing algorithm and the strength of the password. However, the result remains security-relevant because it demonstrates that speculative-execution attacks based on code reuse are not necessarily theoretical, and that software updates alone may not address the root cause before hardware mechanisms are provided to ensure that branch predictions remain consistent with the current code.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news