New Spectre v2 attack variant leaks Linux root password hash in minutes

New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Spectre v2 variant called Branch Target Reuse (BTR) can recover root password hashes from Intel Linux systems in just a few minutes by abusing stale branch-predictor state left behind after JIT code reuse. Researchers from VUSec and Scuola Superiore Sant’Anna demonstrated the attack against Linux cBPF, Firefox SpiderMonkey, and Oracle GraalVM, and Linux kernel fixes have already been merged for CVE-2026-64507 and CVE-2026-64508. #BTR #VUSec #SpiderMonkey #GraalVM #LinuxKernel #CVE-2026-64507 #CVE-2026-64508

Keypoints

  • BTR is a new Spectre v2 attack variant that exploits stale branch predictor data.
  • The attack can recover root password hashes from Intel Linux systems within minutes.
  • VUSec and Scuola Superiore Sant’Anna demonstrated BTR against Linux cBPF, SpiderMonkey, and GraalVM.
  • The exploit works even with constant blinding hardening in Linux cBPF.
  • Linux kernel fixes have been merged, and users should apply OS and firmware updates.

Read More: https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/