Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

BTR Spectre v2 variant leaks Linux root password hash in minutes

Researchers have devised a Spectre v2 attack variant called Branch Target Reuse (BTR) that can recover a Linux root password hash from memory on tested Intel systems in minutes. They report average recovery times of 3 minutes on Raptor Cove and 5 minutes on Lion Cove.

BTR exploits stale information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. In Linux tests, researchers used unprivileged classic BPF programs to train a prediction, replace code at the same address, and make the CPU speculatively execute attacker-crafted instructions. A measurable cache trace then let them infer data byte by byte and recover the hash from a running su process at eight bytes per second.

The researchers evaluated Firefox's SpiderMonkey and Oracle's GraalVM as separate JIT engines. Their SpiderMonkey proof of concept showed that stale predictions survive code reuse, but did not demonstrate a complete browser exploit. In GraalVM, they found a way to speculatively skip a sandbox check, but their experiments did not complete an attack.

A password hash is not the plaintext password; recovering it does not by itself reveal the password. The researchers say they confirmed the behavior on tested Intel, AMD, and Arm CPUs. The issues were assigned CVE-2026-64507 and CVE-2026-64508, and fixes have been merged into the Linux kernel. The source advises users to apply operating system and firmware updates and Linux users to upgrade to the latest kernel. The researchers' findings and exploit details are described in a technical paper.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.