A new Spectre attack has found another crack in the defenses protecting modern processors, and researchers demonstrated it by extracting a Linux root password hash from memory.
Security researchers have disclosed Branch Target Reuse (BTR), a new Spectre v2 attack that targets just-in-time (JIT) compilers and exploits behavior the researchers confirmed on processors from Intel, AMD, and Arm. The researchers built two end-to-end Linux kernel exploits. In their cBPF demonstration on modern Intel CPUs, they leaked arbitrary memory and recovered a root password hash from a running su process in roughly three to five minutes under their test conditions.
The attack does not mean hackers can remotely steal a Linux root password simply by visiting a vulnerable machine. But it demonstrates that speculative-execution weaknesses remain exploitable even after years of Spectre mitigations, particularly when JIT-compiled code and stale processor predictions collide.
How the new Spectre attack works
Researchers from Vrije Universiteit Amsterdam's VUSec group and Scuola Superiore Sant'Anna detailed BTR in a paper accepted to the ACM Conference on Computer and Communications Security (CCS) 2026.
According to the researchers' Branch Target Reuse analysis, the attack exploits a mismatch between JIT-generated code and information retained by a processor's branch predictor.
Modern processors predict where software will execute next to improve performance. When JIT-compiled code is removed and the underlying memory is reused for new code, the processor may retain an old indirect branch prediction pointing to the previous code location.
BTR turns that stale prediction into an attack primitive.
An attacker first trains an indirect branch to target JIT-generated code. That code is then removed, and its memory reused. When the branch executes again, the CPU can speculatively follow the stale prediction into the newly generated code at an unintended location. That speculative execution can expose data that should otherwise remain inaccessible.
The finding adds another wrinkle to a long-running security problem. Spectre v2, also known as Branch Target Injection, was first disclosed in 2018 and abuses speculative execution to cross security boundaries. eSecurityPlanet's Spectre and Meltdown guide explains how the original attacks exploited processor optimizations to expose protected information.
Researchers demonstrate Linux root hash leak
The most striking BTR demonstration targeted the Linux kernel's classic Berkeley Packet Filter (BPF) JIT compiler.
Researchers created two cBPF programs, a training program and a target program, and installed them as seccomp filters. They first executed the training program to train an indirect branch, then removed it and replaced it with the target program in the same memory region.
The processor's stale branch prediction could still point to the old code location. When triggered again, speculative execution could enter the newly generated program at an unintended offset, allowing attacker-controlled instructions to execute transiently.
The researchers said their end-to-end exploit could leak arbitrary memory on modern Intel processors while bypassing all enabled mitigations on their test system.
The proof of concept leaked data at approximately 8 bytes per second. That rate sounds modest, but an attacker does not necessarily need to dump large amounts of memory to obtain something valuable.
The researchers also developed a version of the exploit that bypasses cBPF's optional constant-blinding protection, which is disabled by default. They accomplished this by adapting a JIT-spraying technique that encodes attacker-controlled instructions in jump offsets rather than immediate values.
In the researchers' demonstration, they ran su root, causing the root password hash to be loaded into the process's memory. Their exploit then traversed Linux kernel structures, located the su process and its mapped memory, and ultimately found and leaked the hash.
According to reporting on the researchers' results, the complete demonstration recovered the root password hash in roughly three minutes on Intel Raptor Cove and five minutes on Lion Cove, on average. Those figures reflect specific experimental conditions and should not be treated as universal exploitation times.
The research also does not establish that BTR is currently being used in real-world attacks.
Linux has faced other serious low-level security issues this year. The recently disclosed Januscape Linux VM escape flaw affected KVM systems using Intel and AMD processors and could allow a guest virtual machine to compromise its host.
Intel, AMD, and Arm processors show vulnerable behavior
BTR is not limited to a single CPU vendor.
The researchers said they confirmed the underlying stale branch-prediction behavior on every processor they tested, spanning Intel, AMD, and Arm. They said most systems are likely affected because indirect branch prediction is fundamental to modern CPUs.
That does not mean every Intel, AMD, or Arm system can be exploited using the same technique. Practical exploitation depends heavily on the software environment, JIT engine, available gadgets, and mitigations in place.
The researchers examined three major attack surfaces:
- Linux cBPF: Researchers developed working end-to-end exploits capable of leaking arbitrary memory on tested Intel hardware.
- Mozilla SpiderMonkey: The JavaScript and WebAssembly engine used by Firefox showed conditions that researchers said make BTR attacks feasible. They developed a proof of concept, but an end-to-end browser exploit still requires additional work.
- Oracle GraalVM: Researchers demonstrated a technique to speculatively bypass sandbox memory masking, though GraalVM's compilation and garbage-collection behavior disrupted stale predictor entries before they could complete an end-to-end exploit.
BTR exposes a broader weakness in the interaction between JIT compilers and processor branch prediction, but the researchers did not demonstrate the same level of exploitation across all tested platforms or CPUs.
Browser security remains an important attack surface because malicious webpages can interact with highly optimized JIT engines. Google, for example, recently patched 108 security vulnerabilities in Chrome 154, including critical memory-safety bugs affecting browser components.
Linux and Oracle already deployed BTR mitigations
The researchers privately disclosed their findings to affected hardware and software vendors before making BTR public. As a result, some protections were already available by the time the research was disclosed.
Linux kernel developers deployed fixes for the demonstrated BPF attack before BTR's public disclosure. The two associated vulnerabilities are:
- CVE-2026-64507: Enables an Indirect Branch Prediction Barrier, or IBPB, flush when BPF JIT memory is reused on x86 systems with applicable Spectre v2 mitigations.
- CVE-2026-64508: Adds BPF infrastructure to flush indirect branch predictors before JIT memory is reused, preventing newly written programs from inheriting predictions left by previously executed code.
Linux kernel fixes for both vulnerabilities were published July 25 and have since been incorporated into patched kernel packages and stable branches. Administrators should apply the security updates provided by their Linux distribution.
Oracle also deployed a GraalVM mitigation that randomizes JIT code-cache locations, making predictable region reuse more difficult.
According to the BTR researchers, Mozilla considered IBPB-based mitigations but is prioritizing the completion and deployment of site isolation. Site isolation separates web content into different processes, reducing the sensitive data potentially available within the same address space.
The researchers said hardware vendors acknowledged the findings but pointed to existing mechanisms such as IBPB as the appropriate building blocks for defenses, leaving software vendors to deploy BTR-specific mitigations where needed.
What Linux users and security teams should do
BTR is a research attack, not evidence of an ongoing campaign, but its reach makes the disclosure relevant well beyond the laboratory.
The demonstrated Linux attack should also not be confused with a remote, zero-click compromise. It requires an attacker to run unprivileged code on the target system and access cBPF functionality. In VUSec's demonstration, the researchers installed their cBPF programs as seccomp filters.
Unlike the more powerful eBPF JIT, which is restricted to privileged users, cBPF remains accessible to unprivileged programs. It is still used in Linux Socket Filtering, seccomp filters, and packet-filtering paths used by software including Docker and Chrome, according to the researchers.
Organizations running Linux should apply the latest security updates available from their Linux distribution, particularly on systems where untrusted or lower-privileged code can execute. Administrators should also keep JIT-heavy runtimes, browsers, and development environments up to date as vendors introduce or refine software-specific protections.
The broader lesson is that Spectre did not disappear after the emergency patches of 2018. Modern processors still rely heavily on speculative execution and branch prediction for performance, while JIT compilers continually create, remove, and reuse executable code. BTR shows how the seam between those two systems can create new ways to reach protected data.
For Linux administrators and security teams, CPU-level vulnerabilities are more than an abstract hardware problem. The practical defense may arrive through a Linux kernel update, browser release, or runtime patch rather than a new processor. Keeping those layers current is critical, especially on shared systems where untrusted code and sensitive workloads operate side by side.
Read next: Researchers recently demonstrated another Spectre attack that leaked a JWT from a Cloudflare Worker, showing how speculative-execution attacks can threaten sensitive data in shared cloud environments.





