New Spectre v2 Variant 'Branch Target Reuse' Leaks Linux Root Passwords in Minutes
A novel variant of the **Spectre v2** attack, dubbed Branch Target Reuse (BTR), has been uncovered, demonstrating the ability to extract root password hashes from **Intel**-based Linux systems in mere minutes. This sophisticated transient execution attack exploits stale information within a processor's branch predictor, challenging previous assumptions about the practicality of such exploits against self-modifying code.
A new **Spectre v2** attack variant, termed Branch Target Reuse (BTR), has emerged, capable of recovering root password hashes from **Intel** computers running **Linux** within a few minutes.
BTR exploits residual information in a processor's branch predictor after a just-in-time (JIT) engine reuses memory for new code. By manipulating this leftover data, an attacker can trick the processor into temporarily executing incorrect instructions, potentially exposing sensitive information.
Researchers at **VUsec** (Systems and Network Security Group at **VU Amsterdam**) and **Scuola Superiore Sant'Anna** developed this new attack. They evaluated its practicality against **Firefox**'s **JavaScript** engine **SpiderMonkey**, **GraalVM**, and the **Linux** kernel's cBPF.
**Cristiano Guiffrida** of **VUSec** explained that this finding is significant because, since 2018, the cybersecurity community largely believed such attacks were impractical due to self-modifying code (SMC) forming the basis for dynamic code generation in commodity JIT engines. BTR, however, disproves this, demonstrating that SMC-based transient execution attacks are indeed practical in real-world environments and can be leveraged to leak root password hashes.
The researchers promptly notified affected vendors, leading to the assignment of identifiers **CVE-2026-64507** and **CVE-2026-64508**. Fixes have already been integrated into the **Linux** kernel.
### BTR Leaks Root Password Hash
In the original **Spectre v2** speculative execution side-channel attack, the CPU is deceived into briefly running instructions at a wrongly predicted jump destination, which can expose data via the CPU cache. The BTR variant achieves this by reusing an old prediction after the code at that destination has been replaced, as detailed in the researchers' technical paper.
This new attack exploits a desynchronization between JIT-compiled code and the CPUβs branch predictor. Specifically, when a JIT engine frees code and places new code at the same memory address, the CPU may retain an indirect branch target from the older code.
During a subsequent branch, where the CPU decides which instruction to execute next, it can speculatively, and briefly, execute the new code from that stale target, even though normal execution would follow a different path.

In their **Linux** tests, the researchers employed unprivileged classic BPF programs to train the prediction, free the original program, and then place a different program in the reused memory. The stale target caused the CPU to speculatively execute attacker-crafted instructions at a misaligned offset, leading to data access during speculative execution. This generated a measurable cache trace, allowing the researchers to infer data byte by byte.
They then located a running 'su' process and successfully recovered the root password hash from its memory at a rate of eight bytes per second.
βWe evaluated the end-to-end exploit on both **Raptor Cove** and **Lion Cove**, and leaked the password within 3 and 5 minutes on average, respectively,β the [researchers claim](https://www.vusec.net/projects/btr/).
While leaking a password hash is not equivalent to obtaining the plaintext password, an attacker can attempt to crack the hash offline or using cloud resources. Success depends on the hashing algorithm and the strength of the original password.
The published technical paper demonstrates two end-to-end exploits against **Linux** cBPF: one with the default configuration and another with the constant blinding hardening option enabled. In the latter scenario, the exploit was adapted to encode attacker-controlled instructions in jump offsets, still recovering the hash within five minutes.

The researchers also investigated **Firefox**βs **SpiderMonkey** and **Oracle**βs **GraalVM** as separate JIT engines for BTR exposure.
In **SpiderMonkey**, **VUSec**βs proof-of-concept showed that stale predictions survive code reuse, though it did not lead to a complete browser exploit. For **GraalVM**, the researchers identified a method to speculatively bypass a sandbox check, but the engineβs activity cleared the predictions before they could finalize an attack in their experiments.
### Widespread Vulnerability
Regarding real-world impact, the researchers emphasize that most modern hardware is susceptible to this new BTR attack.
βIndirect branch prediction is inherent to modern CPUs, and BTR exploits the desynchronization between the branch predictor and the actual state of the code,β **VUSec** explained. βNo current CPU has a mechanism to keep the two in sync, so until vendors add one, your CPU is vulnerable.β
βWe confirmed this behavior on every CPU we tested, covering **Intel**, **AMD** and **Arm**.β
Users are advised to apply OS and firmware updates, and **Linux** users are specifically recommended to upgrade to the latest kernel version.
Previous **VUSec** research on speculative execution and CPU microarchitectural attacks includes **RIDL**, **BHI**, **SLAM**, and other attacks targeting modern processors.