thehackernews.com 29 Sept 2026, 17:00 UTC

New Spectre Variant Lets Attackers Recover Linux Root Hashes in Minutes

CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS from VUSec and Scuola Sant’Anna have disclosed a new Spectre v2 variant, Branch Target Reuse (BTR), that targets indirect branch prediction in JIT engines across browsers, language runtimes and the Linux kernel. The flaw arises because modern CPUs may not invalidate stale indirect-branch prediction entries after self-modifying code, allowing attackers to reuse outdated targets when code caches are repopulated.

In JIT contexts, this can create a transient execute-after-free primitive that lets an attacker hijack transient control flow to newly generated code, bypassing some software hardening and exposing data through cache timing side channels. The attack was demonstrated against Mozilla Firefox’s SpiderMonkey, GraalVM and the Linux kernel’s cBPF JIT, with varying exploitability and leakage characteristics.

As proof-of-concept, two end-to-end exploits were developed against the Linux kernel that can leak and recover a root password hash within minutes on a fully patched Intel system with default protections enabled. Mitigations have since been released and merged into the Linux kernel, recorded under CVE-2026-64507 and CVE-2026-64508. The researchers note that GraalVM mitigates region reuse by randomising JIT code-cache locations, while Mozilla has considered IBPB-based mitigations but is prioritising site isolation.

The disclosure follows earlier related work on speculative execution and places BTR as a distinct, JIT-focused pathway that exploits stale BTB entries to influence execution and data leakage, highlighting the need for coordinated fixes across browsers, runtimes and kernel components.

View full article

Article by CyberSIXT