A new Spectre trick can pull a Linux root password hash in minutes

By George Bailey   Published: 09/30/26   4 min read

Researchers at VU Amsterdam’s VUSec lab and Scuola Superiore Sant’Anna published Branch Target Reuse (BTR), a Spectre v2 variant that recovered Linux root password hashes from Intel systems in three to five minutes. The attack is local and unprivileged, but it lands on the same machines where developers run browsers, containers, and shared build agents.

Kernel fixes for CVE-2026-64507 and CVE-2026-64508 are already merged. Treat shared Linux hosts and CI runners as the first patch wave.

If an untrusted process can sit next to su, assume the branch predictor will eventually gossip.

What happened

BTR exploits a gap between just-in-time compiled code and the CPU’s branch predictor. When a JIT frees code and places new code at the same address, the predictor can still remember an old indirect branch target. Speculative execution briefly runs the wrong instructions and leaves a measurable cache trace.

Using classic BPF programs on Linux, the researchers trained that prediction, freed the original program, and placed attacker-controlled code in the reused memory. They then located a running su process and leaked the root password hash at about eight bytes per second. End-to-end recovery averaged three minutes on Raptor Cove and five minutes on Lion Cove. A variant still worked when constant blinding hardening was enabled.

The paper also examined Firefox SpiderMonkey and Oracle GraalVM. SpiderMonkey showed stale predictions surviving code reuse without a full browser exploit in their tests. GraalVM allowed a speculative sandbox-check skip that cleared before a complete attack. VUSec told BleepingComputer the behavior appeared on every CPU they tested across Intel, AMD, and Arm, because no current CPU keeps the branch predictor synchronized with self-modifying code.

Why it matters

This is not a remote unauthenticated RCE. It is a reminder that multi-tenant Linux boxes, student lab machines, and CI runners that allow untrusted code are still speculative-execution terrain. A leaked root hash is not the plaintext password, but offline cracking against weak or reused passwords is routine.

The practical control is boring and effective: keep kernels current, reduce who can run untrusted BPF or JIT workloads beside privileged processes, and prefer short-lived, unique root credentials.

What to do first

Forward this

If you run shared Linux servers, student labs, or CI runners that let people execute their own code: please confirm the hosts are on a kernel that includes this week’s Spectre BTR fixes, and whether unprivileged BPF is still allowed. Researchers showed a local process can pull a root password hash in a few minutes on modern CPUs.

Details

Hunt / verify

Slack paste: Linux: patch kernels for Spectre BTR (CVE-2026-64507/64508), restrict unprivileged BPF on shared hosts, rotate root passwords on multi-user boxes that stayed unpatched.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.