<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr" -->

---
title: New Spectre v2 attack variant leaks Linux root password...
description: Researchers at VUsec and Scuola Superiore Sant&#x27;Anna disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that exploits stale branch predictor...
canonical: https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: New Spectre v2 attack variant leaks Linux root password hash in minutes | daily.dev
og:description: Researchers at VUsec and Scuola Superiore Sant&#x27;Anna disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that exploits stale branch predictor...
og:url: https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr
og:image: https://api.daily.dev/og/posts/l3pZ2cUsR.png
og:image:alt: New Spectre v2 attack variant leaks Linux root password hash in minutes
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# New Spectre v2 attack variant leaks Linux root password hash in minutes

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 1 upvotes · 0 comments

## Summary

Researchers at VUsec and Scuola Superiore Sant'Anna disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that exploits stale branch predictor state after a JIT engine reuses memory for new code. Tested against Linux's cBPF, Firefox's SpiderMonkey, and Oracle's GraalVM, the attack recovered a root password hash from a running 'su' process in 3-5 minutes on Intel Raptor Cove and Lion Cove CPUs, at roughly eight bytes per second, and the researchers confirmed the underlying issue on Intel, AMD, and Arm chips. The issues are tracked as CVE-2026-64507 and CVE-2026-64508, with fixes already merged into the Linux kernel; users are advised to apply OS, firmware, and kernel updates.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes>

## Questions this post answers

### What is the Branch Target Reuse (BTR) Spectre v2 attack and how fast can it leak a Linux root password hash?

BTR is a new Spectre v2 variant that exploits stale branch predictor entries left behind when a JIT engine frees code and reuses the same memory address for new code, tricking the CPU into speculatively executing attacker-crafted instructions. Tested against Linux cBPF, it recovered a root password hash from a running 'su' process at about eight bytes per second, completing in 3 minutes on Intel Raptor Cove and 5 minutes on Lion Cove CPUs.

_Teams hardening Linux kernels against speculative execution flaws can track advisories like this one on daily.dev._

### Which CVEs were assigned to the BTR Spectre v2 attack and has it been patched?

The BTR attack against Linux cBPF and related JIT engines was assigned CVE-2026-64507 and CVE-2026-64508, and fixes have already been merged into the Linux kernel. Users are advised to apply OS and firmware updates and upgrade to the latest kernel version to mitigate the vulnerability.

_Anyone patching Linux systems against new CVEs can follow disclosures like this on daily.dev._

### Does enabling constant blinding in Linux cBPF protect against the BTR Spectre v2 attack?

No, constant blinding does not fully prevent the BTR attack. Researchers demonstrated an end-to-end exploit against cBPF even with the constant blinding hardening option enabled, by adapting the exploit to encode attacker-controlled instructions in jump offsets, still recovering the root password hash within about five minutes.

_Developers evaluating kernel hardening options against speculative execution bugs can follow this research on daily.dev._

## Similar posts on daily.dev

- [New type of attack can slip past the defenses in your computer’s processor](https://daily.dev/posts/new-type-of-attack-can-slip-past-the-defenses-in-your-computer-s-processor-hhyhhdxyi) · MIT News · 0 upvotes · 0 comments
- [The Surprising Spectre BHI Mitigation Performance Impact On Meteor Lake](https://daily.dev/posts/the-surprising-spectre-bhi-mitigation-performance-impact-on-meteor-lake-vihagkioh) · Phoronix · 0 upvotes · 0 comments
- [Newer RISC-V CPUs Vulnerable To Spectre V1 - Linux Mitigation Patches Posted](https://daily.dev/posts/newer-risc-v-cpus-vulnerable-to-spectre-v1---linux-mitigation-patches-posted-w75vepfxx) · Phoronix · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux)

[View this post on daily.dev](https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"New Spectre v2 attack variant leaks Linux root password hash in minutes","url":"https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr"},"datePublished":"2026-09-29T17:12:22.817Z","dateModified":"2026-09-29T17:58:01.462Z","description":"Researchers at VUsec and Scuola Superiore Sant'Anna disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that exploits stale branch predictor...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/361fe4d2bf67e1c685ed3cc28778fed8?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/361fe4d2bf67e1c685ed3cc28778fed8?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"New Spectre v2 attack variant leaks Linux root password hash in minutes"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes-l3pz2cusr#faq","mainEntity":[{"@type":"Question","name":"What is the Branch Target Reuse (BTR) Spectre v2 attack and how fast can it leak a Linux root password hash?","acceptedAnswer":{"@type":"Answer","text":"BTR is a new Spectre v2 variant that exploits stale branch predictor entries left behind when a JIT engine frees code and reuses the same memory address for new code, tricking the CPU into speculatively executing attacker-crafted instructions. Tested against Linux cBPF, it recovered a root password hash from a running 'su' process at about eight bytes per second, completing in 3 minutes on Intel Raptor Cove and 5 minutes on Lion Cove CPUs. Teams hardening Linux kernels against speculative execution flaws can track advisories like this one on daily.dev."}},{"@type":"Question","name":"Which CVEs were assigned to the BTR Spectre v2 attack and has it been patched?","acceptedAnswer":{"@type":"Answer","text":"The BTR attack against Linux cBPF and related JIT engines was assigned CVE-2026-64507 and CVE-2026-64508, and fixes have already been merged into the Linux kernel. Users are advised to apply OS and firmware updates and upgrade to the latest kernel version to mitigate the vulnerability. Anyone patching Linux systems against new CVEs can follow disclosures like this on daily.dev."}},{"@type":"Question","name":"Does enabling constant blinding in Linux cBPF protect against the BTR Spectre v2 attack?","acceptedAnswer":{"@type":"Answer","text":"No, constant blinding does not fully prevent the BTR attack. Researchers demonstrated an end-to-end exploit against cBPF even with the constant blinding hardening option enabled, by adapting the exploit to encode attacker-controlled instructions in jump offsets, still recovering the root password hash within about five minutes. Developers evaluating kernel hardening options against speculative execution bugs can follow this research on daily.dev."}}]}
```

