vulnerability
Published 2026-09-29
Verified 2026-09-30

Spectre-v2 Branch Target Reuse (BTR): CVE-2026-64507/64508 — Linux cBPF JIT leaks root password hash in minutes (VUSec)

VUSec (VU Amsterdam) with Scuola Superiore Sant’Anna (29 September 2026 project page; BleepingComputer / The Hacker News / SecurityWeek amplify) disclose Branch Target Reuse (BTR), a Spectre-v2 variant against JIT engines. After self-modifying code frees and reuses an address, CPUs may keep stale indirect-branch prediction entries, yielding speculative execute-after-free into newly generated code at obsolete offsets. Evaluated on Linux classic BPF (cBPF) JIT, Firefox SpiderMonkey, and Oracle GraalVM; behaviour confirmed across Intel, AMD and Arm CPUs tested. End-to-end Linux cBPF path (seccomp filters; unprivileged): leak ~8 bytes/s and recover the root password hash from a concurrent su process in about 3–5 minutes on Raptor Cove / Lion Cove (Intel). Also bypasses optional bpf_jit_harden constant blinding by encoding gadgets in jump offsets. Linux kernel mitigations merged: CVE-2026-64507 (x86/bugs: Enable IBPB flush on BPF JIT allocation) and CVE-2026-64508 (bpf: Support for hardening against JIT spraying). GraalVM: randomise JIT code-cache locations (oracle/graal PR 14261). Mozilla: prioritising site isolation over IBPB-based browser mitigations; SpiderMonkey showed stale BTB survival but no complete browser exploit published. Primary: VUSec BTR project; wires: BleepingComputer / THN / SecurityWeek 29 Sep.

Product
Linux kernel cBPF/seccomp JIT; Firefox SpiderMonkey JIT; Oracle GraalVM JIT; Intel/AMD/Arm CPUs (indirect branch prediction)
Versions
Mitigations merged into Linux kernel for CVE-2026-64507 and CVE-2026-64508 (upgrade to a kernel that includes those fixes). GraalVM: apply JIT code-cache randomisation (oracle/graal PR 14261). Firefox: no complete browser exploit published; site-isolation work ongoing per VUSec.
Exploited in Australia?
unknown
Patch to
Linux: upgrade to a kernel that includes CVE-2026-64507/64508 BTR mitigations (IBPB flush on BPF JIT allocation + JIT-spray hardening); consider bpf_jit_harden where appropriate (does not alone stop BTR). Apply GraalVM / runtime updates that randomise JIT code-cache placement. Browser users: keep Firefox/OS current; treat untrusted pages as hostile to same-process tabs until site isolation is complete. Hardware: no CPU sync for BTB vs code state yet — OS/runtime patches are the near-term control.

Primary: VUSec — Branch Target Reuse (BTR) project page (primary research) · Vendor: VUSec / Scuola Superiore Sant’Anna — BTR disclosure · CVE: CVE-2026-64507, CVE-2026-64508 · BleepingComputer — New Spectre v2 BTR leaks Linux root password hash (29 Sep 2026)

vulnerabilities network