News / Cybersecurity
New Spectre v2 flaw: Branch Target Reuse (BTR) exposes Linux root passwords in minutes Published on 29 September 2026 by Christ-loisele (3 min read)
Researchers from VUsec and Scuola Superiore Sant'Anna have discovered a Spectre v2 variant, Branch Target Reuse (BTR), capable of retrieving root password hashes under Linux by exploiting Intel branch predictors. Patches are already integrated into the Linux kernel.
Video: Branch Target Reuse (BTR) exploit: Leaking the root password hash from the "su" process! (VUSec, YouTube)
A flaw exploiting Intel branch predictors
The Branch Target Reuse (BTR) variant of Spectre v2 allows retrieving sensitive data, such as Linux root password hashes, by manipulating branch predictions in Intel processors. According to BleepingComputer , researchers from VUsec (Vrije Universiteit Amsterdam) and Scuola Superiore Sant'Anna demonstrated that this attack bypasses security assumptions established since 2018, which deemed such attacks unfeasible.
The exploit relies on a desynchronization between the branch predictor and the actual state of the code after memory reuse by a JIT (Just-In-Time) engine. By measuring cache traces, attackers can reconstruct data byte by byte, such as the root password hash, at a rate of eight bytes per second. Tests confirmed this method works on Intel Raptor Cove and Lion Cove CPUs, with an average time of 3 to 5 minutes to extract the hash.
No current CPU has a mechanism to synchronize branch predictions with the actual state of the code, leaving systems vulnerable until manufacturers intervene.
Image: vusec (official image)
Confirmed vulnerabilities on Firefox, GraalVM, and the Linux kernel
Researchers validated the attack on three targets: Firefox’s SpiderMonkey engine, GraalVM, and the Linux kernel’s cBPF module. The Hacker News notes that BTR exploits obsolete indirect prediction entries, persisting after code rewriting (Self-Modifying Code). Even with protections like constant blinding enabled in cBPF, the root password hash was retrieved in five minutes.
Firefox retains obsolete predictions after memory reuse, though no full browser exploitation has been demonstrated. GraalVM partially mitigates the risk by randomizing JIT cache locations, but predictions are erased before the attack concludes.
Image: vusec (official image)
Patches integrated, but a persistent vulnerability on modern CPUs
The fixes for BTR have been merged into the Linux kernel under references The Hacker News CVE-2026-64507 and CVE-2026-64508. However, the vulnerability affects all modern processors using indirect prediction mechanisms, including those from Intel, AMD, and Arm. Researchers note that no current CPU automatically synchronizes predictions with the architectural state of the code, leaving systems exposed until manufacturers add countermeasures.
Logo: Scuola Superiore Sant'Anna (Sant'Anna School of Advanced Studies, CC BY-SA 4.0)
What this changes here
For businesses and government agencies in Benin and West Africa, this flaw could strengthen the need to update Linux systems to versions including the fixes CVE-2026-64507 and CVE-2026-64508, especially on critical servers or environments with high privileges. Organizations using JIT engines like Firefox or GraalVM should also assess the risks related to applications running untrusted code , as unauthorized code execution could theoretically exploit BTR to extract sensitive data.
Public administrations, whose infrastructures are often targeted, could strengthen system process isolation and limit access to root accounts, while companies using local clouds or dedicated servers should check the compatibility of their CPUs with future mitigations , as the vulnerability concerns the architecture of the processors themselves.
Sources