Researchers at VU Amsterdam’s VUSec lab and Scuola Superiore Sant’Anna published Branch Target Reuse (BTR), a Spectre v2 variant that recovered Linux root password hashes from Intel systems in three to five minutes. The attack is local and unprivileged, but it lands on the same machines where developers run browsers, containers, and shared build agents.
Kernel fixes for CVE-2026-64507 and CVE-2026-64508 are already merged. Treat shared Linux hosts and CI runners as the first patch wave.
If an untrusted process can sit next to
su, assume the branch predictor will eventually gossip. The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
BTR exploits a gap between just-in-time compiled code and the CPU’s branch predictor. When a JIT frees code and places new code at the same address, the predictor can still remember an old indirect branch target. Speculative execution briefly runs the wrong instructions and leaves a measurable cache trace.
Using classic BPF programs on Linux, the researchers trained that prediction, freed the original program, and placed attacker-controlled code in the reused memory. They then located a running su process and leaked the root password hash at about eight bytes per second. End-to-end recovery averaged three minutes on Raptor Cove and five minutes on Lion Cove. A variant still worked when constant blinding hardening was enabled.
The paper also examined Firefox SpiderMonkey and Oracle GraalVM. SpiderMonkey showed stale predictions surviving code reuse without a full browser exploit in their tests. GraalVM allowed a speculative sandbox-check skip that cleared before a complete attack. VUSec told BleepingComputer the behavior appeared on every CPU they tested across Intel, AMD, and Arm, because no current CPU keeps the branch predictor synchronized with self-modifying code.
Why it matters
This is not a remote unauthenticated RCE. It is a reminder that multi-tenant Linux boxes, student lab machines, and CI runners that allow untrusted code are still speculative-execution terrain. A leaked root hash is not the plaintext password, but offline cracking against weak or reused passwords is routine.
The practical control is boring and effective: keep kernels current, reduce who can run untrusted BPF or JIT workloads beside privileged processes, and prefer short-lived, unique root credentials.
What to do first
- Patch Linux kernels that include the BTR fixes for CVE-2026-64507 and CVE-2026-64508; prioritize multi-user hosts, VDI, and CI runners.
- Limit unprivileged BPF on shared hosts where you do not need it (
kernel.unprivileged_bpf_disabledwhere operationally acceptable). - Rotate root and break-glass passwords on hosts that allowed untrusted local code while unpatched, especially if password hashes are reused elsewhere.
- Keep browsers and JVM/JIT runtimes updated on developer workstations that process untrusted content.
- Prefer SSH keys / SSO over password-based root escalation where you can.
Forward this
If you run shared Linux servers, student labs, or CI runners that let people execute their own code: please confirm the hosts are on a kernel that includes this week’s Spectre BTR fixes, and whether unprivileged BPF is still allowed. Researchers showed a local process can pull a root password hash in a few minutes on modern CPUs.
Details
- Name: Branch Target Reuse (BTR), Spectre v2 variant
- CVEs: CVE-2026-64507, CVE-2026-64508
- Researchers: VUSec (VU Amsterdam) and Scuola Superiore Sant’Anna; public coverage Sep 29, 2026
- Demonstrated impact: unprivileged local leak of Linux root password hash in ~3 to 5 minutes on Intel Raptor Cove / Lion Cove
- Also examined: Firefox SpiderMonkey, Oracle GraalVM (incomplete end-to-end browser/JVM exploits in the paper)
- Hardware note: researchers report the desynchronization on Intel, AMD, and Arm CPUs tested; OS/firmware updates are the near-term mitigation
Hunt / verify
- Confirm kernel package versions on shared hosts include the Sep 2026 BTR patches.
- Inventory where unprivileged users can load cBPF/eBPF programs.
- Review whether CI jobs run untrusted pull requests on runners that also hold privileged secrets.
- Check for unexpected local user accounts or long-lived shared root passwords on lab and jump hosts.
Slack paste: Linux: patch kernels for Spectre BTR (CVE-2026-64507/64508), restrict unprivileged BPF on shared hosts, rotate root passwords on multi-user boxes that stayed unpatched.
Sources
- BleepingComputer: New Spectre v2 attack variant leaks Linux root password hash in minutes (Sep 29, 2026)
- VUSec research group
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.