Full Report
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]
Analysis Summary
# Vulnerability: Branch Target Reuse (BTR) Spectre v2 Variant
## CVE Details
- **CVE ID**: CVE-2026-64507, CVE-2026-64508
- **CVSS Score**: Not yet finalized (Estimated High/Critical for local privilege escalation/data leakage)
- **CWE**: CWE-1037 (Data Exposure Between Parallel Transactions), CWE-1191 (On-Chip Debug and Test Interface with Improper Access Control)
## Affected Systems
- **Products**:
- Intel CPUs (specifically confirmed on Raptor Cove and Lion Cove architectures).
- AMD and Arm CPUs (confirmed vulnerable to the underlying branch prediction behavior).
- Linux Kernel (specifically cBPF subsystem).
- JIT Engines: Firefox SpiderMonkey, Oracle GraalVM.
- **Versions**: All Linux versions prior to the September 2026 security patches.
- **Configurations**: Systems running Linux with unprivileged BPF enabled; environments using Just-In-Time (JIT) engines that reuse memory for dynamic code generation.
## Vulnerability Description
Branch Target Reuse (BTR) is a variant of the Spectre-v2 speculative execution attack. It exploits a desynchronization between a CPU’s branch predictor and the actual state of memory when code is dynamically generated.
When a JIT engine (like Linux's cBPF or Firefox's SpiderMonkey) frees a memory region and then reuses that same address for new code, the CPU's branch predictor may still hold "stale" indirect branch targets from the previous code. An attacker can use an unprivileged process to train the branch predictor. When a privileged process subsequently reuses that memory, the CPU may speculatively execute instructions at a misaligned offset based on the stale prediction. This transient execution creates a cache side-channel, allowing the attacker to leak sensitive data (such as root password hashes) from kernel or process memory.
## Exploitation
- **Status**: PoC available (demonstrated by VUsec researchers).
- **Complexity**: High (requires precise timing and memory manipulation).
- **Attack Vector**: Local (requires the ability to run unprivileged code on the target system).
## Impact
- **Confidentiality**: High (Demonstrated recovery of root password hashes at 8 bytes per second).
- **Integrity**: None (Side-channel attack; read-only).
- **Availability**: None.
## Remediation
### Patches
- **Linux Kernel**: Fixes have been merged into the Linux kernel (September 2026). Users should update to the latest stable kernel provided by their distribution.
- **Microcode/Firmware**: While software patches exist, full remediation may require future CPU microcode updates to synchronize the branch predictor with memory state changes.
### Workarounds
- **Disable Unprivileged BPF**: Restricting BPF access to administrative users can mitigate the primary attack vector used in the PoC.
- **Constant Blinding**: While the researchers demonstrated an exploit that bypasses constant blinding, maintaining this hardening makes exploitation more difficult.
## Detection
- **Indicators of Compromise**: High CPU usage in short bursts associated with JIT-heavy applications or BPF program loading/unloading.
- **Detection Methods**: Monitoring for unusual cache-miss patterns or timing attacks using performance counters (e.g., `perf`), though this is difficult to distinguish from legitimate system activity.
## References
- **Vendor Advisories**: Linux Kernel Security Team
- **Relevant Links**:
- hxxps[://]www[.]vusec[.]net/projects/btr/
- hxxps[://]www[.]bleepingcomputer[.]com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
- hxxps[://]www[.]youtube[.]com/watch?v=6en6nmF6Uyc