Spectre-v2 BTR Attack Leaks Root Password Hash from Patched Linux
AI-generated image

Spectre-v2 BTR Attack Leaks Root Password Hash from Patched Linux

Researchers demonstrated a new Spectre-v2 variant named BTR that steals the root password hash from a fully patched Intel Linux system in minutes, bypassing exi…

A new variant of the Spectre-v2 CPU vulnerability, called Branch Target Reuse (BTR), can leak sensitive kernel memory on fully patched Linux systems, even with default protections enabled. Security researchers from VUSec and Scuola Superiore Sant'Anna disclosed the attack, which targets just-in-time (JIT) compilation engines inside web browsers, language runtimes, and the operating system kernel itself. In a proof-of-concept exploit, they extracted the root password hash from a modern Intel system in a matter of minutes, showing that years of hardware and software mitigations still leave exploitable gaps.

The core of BTR lies in how modern processors handle speculative execution, a performance trick where the CPU guesses which instructions come next and runs them ahead of time, then discards wrong guesses. Spectre-v2 specifically abuses indirect branch prediction, the mechanism the CPU uses to remember where a program typically jumps after a certain instruction. BTR adds a new twist: it exploits a disconnect between self-modifying code and the branch target buffer (BTB), a hardware table that stores those jump predictions. When a JIT engine generates code on the fly, frees it, and later reuses the same memory address for new code, the old, stale BTB entry can survive. The CPU may then speculatively jump to the outdated entry point, hijacking transient execution and leaking secrets from memory.

The researchers explained the attack in three stages. First, an unprivileged attacker lures the JIT engine into allocating a training chunk of code and forces a specific indirect branch to jump there, planting a BTB entry tied to that address. Next, the attacker triggers the engine to free that memory and allocate a new, target chunk that partially overlaps the old address. Finally, by triggering the indirect branch again, the CPU consults the now-stale BTB entry and speculatively leaps to the old entry point, which now holds attacker-chosen code. Because the CPU temporarily executes this wrong path before realizing the mistake, the attacker can measure subtle changes in the CPU’s cache timing to infer data that would normally be off-limits, such as kernel memory contents.

The attack was confirmed against several JIT engines: SpiderMonkey (Mozilla Firefox’s JavaScript engine), the GraalVM runtime's JIT compiler, and the Linux kernel’s classic Berkeley Packet Filter (cBPF) JIT. All three were found vulnerable, though with different ease of exploitation and leakage rates. The researchers built two end-to-end exploits targeting the Linux kernel cBPF JIT, proving that an attacker with unprivileged local access can recover the root password hash from a machine running a fully updated Intel system. The entire leak takes only minutes, making BTR a practical threat in shared hosting environments, container setups, and anywhere attackers can run code inside a JIT engine.

Mitigations are already underway. Two vulnerabilities, CVE-2026-64507 and CVE-2026-64508, have been assigned and patches merged into the mainline Linux kernel. GraalVM has addressed the issue by randomizing the locations of its JIT code cache, making it harder to predict address reuse. Mozilla is evaluating an approach based on Indirect Branch Predictor Barriers (IBPB), a feature that can flush the BTB, but is currently focusing on completing the rollout of site isolation in Firefox, which separates browsing contexts into independent processes to limit the damage any one attack can do. The disclosure follows another recent speculative execution finding called Interrupt Injection, reported by MIT CSAIL researchers, which also bypassed Spectre-v2 defenses on Intel and AMD systems.

For website owners and businesses that rely on Linux servers, BTR underscores the challenge of defending against hardware-level attacks that slip past software patches. Even a fully updated kernel can harbor exploitable side-channels until specialized mitigations land. A managed hosting provider like AEU Hosting takes that worry off your shoulders by applying kernel patches and security hardening as part of its end-to-end WordPress hosting service, ensuring your server environment stays protected without you having to track every new CVE. Meanwhile, ordinary users can reduce risk by keeping their browsers and operating systems current, enabling hardware-based safeguards like Intel’s Indirect Branch Restricted Speculation (IBRS) where available, and exercising caution when running untrusted code in any JIT-heavy application.

How to Protect Yourself

  1. If you run your own Linux server, apply the most recent kernel updates from your distribution today, which include fixes for these Spectre-v2 flaws.
  2. Contact your hosting provider and ask whether they have installed the latest Linux kernel security patches on your server.
  3. Keep your web browser (especially Firefox) updated, as vendors are working on built-in protections that limit such leaks from malicious websites.
  4. Enable site isolation in Firefox by typing about:preferences#privacy in the address bar and confirming that strict tracking protection or fission is active, which helps contain attacks.
  5. Run only trusted software and avoid executing unknown scripts or programs that could try to exploit local JIT engines.

Vulnerabilities & Fixes

Terms Explained

  • Spectre A class of CPU flaws that trick the processor into leaking private data by exploiting its habit of guessing ahead, discovered in 2017.
  • Speculative execution A performance technique where a CPU runs instructions before it knows they are definitely needed, discarding the results if the guess was wrong.
  • JIT (Just-In-Time) engine A software component that compiles and runs code on the fly, commonly found in browsers and programming language runtimes to speed up execution.
  • BTB (Branch Target Buffer) A small memory inside the CPU that stores where a program is likely to jump next based on past behavior, used to predict branches.
  • cBPF (classic Berkeley Packet Filter) An older in-kernel virtual machine used in Linux for network packet filtering, which includes a JIT compiler that was targeted by the BTR attack.
  • BTR (Branch Target Reuse) The name given to this new Spectre-v2 variant, which reuses stale branch prediction entries left behind after code is freed and replaced.

Related AEU services