VUSec reports that Branch Target Reuse (BTR), a Spectre v2 attack, recovered a Linux root password hash through the classic Berkeley Packet Filter (cBPF) just-in-time compiler. The group describes two end-to-end exploits and says Linux kernel developers upstreamed an x86 mitigation. The result was a hash—not the plaintext password.
Branch Target Reuse and the Linux hash demonstration
A password hash is a one-way representation used to check a password. Recovering it does not reveal the password itself; an attacker would still have to crack the hash, with the odds depending on the hashing algorithm and password strength.
VUSec says its demonstration placed the root password hash in memory by running su root, then used the Linux cBPF JIT to leak it. The group reports a leakage rate of eight bytes per second. It also describes two end-to-end exploits: one in the default configuration and another that bypassed cBPF constant blinding, a defense that obscures constants in compiled code.
Separate reported averages attributed to the researchers put end-to-end hash recovery at three minutes on Intel Raptor Cove and five minutes on Intel Lion Cove.
How stale predictions meet reused JIT code
BTR targets a mismatch between a processor’s branch predictor and the code currently occupying memory. A branch predictor guesses where execution will go next. When a JIT engine frees compiled code and later reuses the same address for different code, an old indirect-branch prediction can persist. The processor may then speculatively execute the new code at an obsolete offset.
In VUSec’s Linux demonstration, unprivileged cBPF programs installed as seccomp filters supplied the code used in the attack. The sequence depends on reusing a code region while a stale prediction remains; the demonstrated outcome was a hash leak, not automatic recovery of a password in plain text. VUSec’s project page describes the mechanism and Linux results: VUSec’s BTR project.
Linux, SpiderMonkey, and GraalVM results
The Linux cBPF work is the end-to-end hash-leak demonstration. VUSec’s browser-engine findings are more limited. In Firefox SpiderMonkey, the group reports a proof of concept showing that stale predictions survived code reuse, but not a complete browser exploit. In Oracle GraalVM, the experiments explored speculative bypass of a sandbox mask; compilation and garbage collection cleared branch-prediction entries before an attack was completed. VUSec says Oracle mitigated code-region reuse in GraalVM by randomizing JIT code-cache locations.
VUSec also says it confirmed the behavior on every CPU it tested across Intel, AMD, and Arm. That statement concerns the tested processors; it does not mean the Linux hash-recovery demonstration was completed on every vendor’s CPUs.
The reported Linux mitigation
VUSec says Linux kernel developers upstreamed an x86 mitigation that issues an Indirect Branch Prediction Barrier (IBPB) across all cores when a cBPF program reuses a previously executed cBPF or eBPF code region. The change also discourages that reuse. VUSec lists the related identifiers as CVE-2026-64507 and CVE-2026-64508.
VUSec recommends applying operating-system and software updates when vendor patches are available.
The scheduled paper
VUSec says its paper on Branch Target Reuse was accepted for ACM CCS 2026 and scheduled for publication in November 2026.