{"id":2097,"date":"2026-09-30T14:42:24","date_gmt":"2026-09-30T09:12:24","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=2097"},"modified":"2026-10-05T12:10:16","modified_gmt":"2026-10-05T06:40:16","slug":"branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/","title":{"rendered":"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash"},"content":{"rendered":"<p>Researchers have disclosed Branch Target Reuse, a new Spectre v2 variant that recovers a Linux root password hash in minutes. VUsec and Scuola Superiore Sant&#8217;Anna built the attack and tested it against Firefox&#8217;s SpiderMonkey engine, Oracle GraalVM, and the Linux kernel&#8217;s classic BPF path.<\/p>\n<p>The attack requires no special privileges. An unprivileged local user can train the processor&#8217;s branch predictor, then abuse leftover prediction data after a just-in-time engine frees and reuses code memory.<\/p>\n<p>For enterprise security teams, this matters because it bypasses assumptions that have held since 2018. Researchers previously believed self-modifying JIT code made this class of speculative execution attack impractical. BTR shows that assumption no longer holds.<\/p>\n<h2>How Branch Target Reuse breaks JIT code isolation<\/h2>\n<p>Branch Target Reuse targets a timing gap between JIT-compiled code and the CPU&#8217;s branch predictor. The mechanism works in stages:<\/p>\n<ul>\n<li>A JIT engine allocates a code chunk, and the attacker trains an indirect branch to jump to it.<\/li>\n<li>The engine frees that chunk and allocates a new one at the same memory address.<\/li>\n<li>The CPU&#8217;s branch predictor still holds the old, now-stale target for that address.<\/li>\n<\/ul>\n<p>On the next indirect branch, the CPU speculatively executes the new code at the old, misaligned offset before it restores correct execution.<\/p>\n<p>VUSec&#8217;s Cristiano Giuffrida told BleepingComputer that BTR proves self-modifying code does not block this attack class, contrary to prior assumptions. The researchers confirmed the underlying branch-predictor desynchronization on Intel, AMD, and Arm processors.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-analysis-.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Analysis?<\/h4><p>Threat analysis explained: process, tools, techniques, and Hexnode XDR support.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-analysis\/\" aria-label=\"What is Threat Analysis?\"><\/a><\/div><\/div><\/div>\n<h2>Recovering a root password hash from a live process<\/h2>\n<p>The Linux proof of concept uses unprivileged classic BPF (cBPF) programs, which remain available to non-root users even though the more powerful eBPF JIT is privilege-restricted. The researchers explain that cBPF&#8217;s simplicity, limited to two registers and forward jumps only, is why it was historically treated as safe for filters used by Docker, Chrome, and network packet filtering.<\/p>\n<p>Their exploit chain works like this:<\/p>\n<ul>\n<li>Install a training cBPF program as a seccomp filter to prime the stale branch target.<\/li>\n<li>Remove that program and install a second cBPF program in the same memory region.<\/li>\n<li>Trigger the stale prediction to speculatively execute attacker-crafted bytes at a misaligned offset.<\/li>\n<li>Read the resulting cache timing pattern to infer memory contents one byte at a time.<\/li>\n<\/ul>\n<p>The researchers walked the kernel&#8217;s task list to locate a running su process, then leaked its page tables to extract the root password hash. The technique recovers data at eight bytes per second. VUsec reported an average recovery time of three minutes on Intel&#8217;s Raptor Cove and five minutes on Lion Cove.<\/p>\n<p>The attack also defeats bpf_jit_harden, the kernel&#8217;s constant-blinding option. Researchers adapted a 2016 jump-offset encoding technique to hide attacker-controlled bytes inside forward-jump offsets instead of immediate values, still recovering the hash within five minutes with hardening enabled.<\/p>\n<p>Setting <code>kernel.unprivileged_bpf_disabled=1<\/code> blocks this specific attack path, since it removes unprivileged users&#8217; access to the cBPF training step the exploit depends on. This sysctl change works as an immediate stopgap before kernel patches land, not a permanent replacement for them.<\/p>\n<p>Leaking a hash is not the same as obtaining a plaintext password. An attacker still needs to crack that hash offline, and success depends on the hashing algorithm and password strength.<\/p>\n<h2>Exposure beyond Linux stays limited so far<\/h2>\n<p>The researchers also tested two non-Linux JIT engines:<\/p>\n<ul>\n<li><strong>Firefox SpiderMonkey:<\/strong> <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-proof-of-concept-poc-in-cybersecurity\/\">Proof-of-concept<\/a> work confirmed stale branch predictions survive code reuse and could reach WebAssembly literal pools. Researchers did not build a complete browser exploit.<\/li>\n<li><strong>Oracle GraalVM:<\/strong> Researchers found a way to skip a <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-sandboxing\/\">sandbox<\/a> masking check speculatively, but GraalVM&#8217;s own compilation and garbage-collection activity cleared the stale predictions before they could complete an attack in testing.<\/li>\n<\/ul>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 22.6215%; text-align: left;\"><strong>Component<\/strong><\/th>\n<th style=\"width: 39.9577%; text-align: left;\"><strong>Exploitation Status<\/strong><\/th>\n<th style=\"width: 36.4693%; text-align: left;\"><strong>Operational Priority<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 22.6215%;\">Linux kernel cBPF<\/td>\n<td style=\"width: 39.9577%;\">Working end-to-end exploit, including a bypass of constant-blinding hardening<\/td>\n<td style=\"width: 36.4693%;\">Critical: apply kernel patches immediately<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 22.6215%;\">Firefox SpiderMonkey<\/td>\n<td style=\"width: 39.9577%;\">Stale predictions confirmed; no complete browser exploit built<\/td>\n<td style=\"width: 36.4693%;\">Monitor: Mozilla is prioritizing site isolation instead<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 22.6215%;\">Oracle GraalVM<\/td>\n<td style=\"width: 39.9577%;\">Sandbox bypass demonstrated but blocked by engine timing in testing<\/td>\n<td style=\"width: 36.4693%;\">Lower: vendor mitigation already shipped<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Vendor fixes and remaining gaps<\/h2>\n<p>The Linux kernel team assigned two identifiers to the disclosed fixes. <a href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2026-64507?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=branch_target_reuse\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-64507<\/a> covers a new IBPB flush issued when the x86 BPF JIT reuses memory. <a href=\"https:\/\/access.redhat.com\/security\/cve\/cve-2026-64508?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=branch_target_reuse\" target=\"_blank\" rel=\"nofollow noopener\">CVE-2026-64508<\/a> covers the underlying hardening support that flushes branch predictors on JIT memory reuse. Third-party trackers currently list differing preliminary severity scores for these entries, and NVD&#8217;s own analysis remains pending, so treat published scores as provisional rather than final.<\/p>\n<p>Other affected vendors took different paths. Oracle addressed its exposure by randomizing GraalVM&#8217;s JIT code-cache locations, which reduces the chance of address reuse. Mozilla considered IBPB-based mitigations for SpiderMonkey but is currently prioritizing the completion and deployment of site isolation.<\/p>\n<p>VUSec&#8217;s own guidance flags limits to existing hardware defenses:<\/p>\n<ul>\n<li>Indirect Branch Tracking and Branch Target Identification raise the bar but do not eliminate the risk.<\/li>\n<li>Older Intel chips can still execute one or more instructions speculatively before those checks apply.<\/li>\n<li>Lion Cove is the first Intel generation VUSec found to close that race window.<\/li>\n<\/ul>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Cybersecurity kit with blueprint, framework guide, checklist, incident policy template, and UEM infographic included.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Patch and endpoint Hardening Guidance<\/h2>\n<p>Fixing this exposure means updating the Linux kernel itself, not just patching applications running on top of it. Distinguish two separate hardening tasks:<\/p>\n<ul>\n<li><strong>Server and workstation kernels:<\/strong> Apply the latest kernel update containing the IBPB flush mitigation as soon as your distribution ships it.<\/li>\n<li><strong>Interim exposure reduction:<\/strong> Audit kernel versions across Linux endpoints via your UEM or MDM console to find unpatched systems, and where patching is delayed, disable unprivileged BPF with <code>sysctl kernel.unprivileged_bpf_disabled=1<\/code> to block the cBPF training path the exploit relies on.<\/li>\n<\/ul>\n<p>Endpoint patch hygiene on admin or developer laptops does not remediate this flaw by itself. The exposure lives in the kernel and JIT engines running on every affected machine, so teams need visibility into kernel version and patch status across the full Linux fleet, not just perimeter systems.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does patching CVE-2026-64507 and CVE-2026-64508 fully close Branch Target Reuse?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>These fixes address the Linux kernel&#8217;s cBPF exposure specifically. SpiderMonkey and GraalVM require separate, engine-specific mitigations, and Firefox&#8217;s fix is still pending.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is Branch Target Reuse limited to Intel processors?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. VUSec confirmed the underlying branch-predictor desynchronization on Intel, AMD, and Arm CPUs. The fast three-to-five-minute exploit was demonstrated specifically on Intel Raptor Cove and Lion Cove.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does enabling Indirect Branch Tracking or Branch Target Identification stop this attack?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>These controls raise the difficulty but do not eliminate the risk on their own. VUSec found exploitable gaps on older Intel chips and notes that exploitable gadgets may still exist on the speculative return path.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>Branch Target Reuse shows that speculative execution risk did not disappear with earlier Spectre mitigations. A local, unprivileged user can still recover a Linux root password hash in minutes using nothing more than standard cBPF programs.<\/p>\n<p>Security teams should treat kernel and <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-firmware-security\/\">firmware<\/a> updates as the priority fix, not an optional hardening step. Reducing local attack surface on Linux endpoints and tracking patch status across the fleet further limits exposure while vendor fixes for browser and runtime JIT engines continue to develop.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay ahead of kernel-level threats. <\/h5><p>Get patch visibility across your entire Linux fleet today. \r\n<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Researchers have disclosed Branch Target Reuse, a new Spectre v2 variant that recovers a Linux&#8230;<\/p>\n","protected":false},"author":5,"featured_media":2128,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,21],"class_list":["post-2097","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-patch-management","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash<\/title>\n<meta name=\"description\" content=\"Branch Target Reuse (BTR), a new Spectre v2 variant, leaks Linux root password hashes in minutes. See CVE-2026-64507 and CVE-2026-64508.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash\" \/>\n<meta property=\"og:description\" content=\"Branch Target Reuse (BTR), a new Spectre v2 variant, leaks Linux root password hashes in minutes. See CVE-2026-64507 and CVE-2026-64508.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-30T09:12:24+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-05T06:40:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/branch-target-reuse.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash\",\"datePublished\":\"2026-09-30T09:12:24+00:00\",\"dateModified\":\"2026-10-05T06:40:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/\"},\"wordCount\":1230,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/branch-target-reuse.jpeg?format=webp\",\"articleSection\":[\"Zero-Day\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/\",\"name\":\"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/branch-target-reuse.jpeg?format=webp\",\"datePublished\":\"2026-09-30T09:12:24+00:00\",\"dateModified\":\"2026-10-05T06:40:16+00:00\",\"description\":\"Branch Target Reuse (BTR), a new Spectre v2 variant, leaks Linux root password hashes in minutes. See CVE-2026-64507 and CVE-2026-64508.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/branch-target-reuse.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/branch-target-reuse.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"branch target reuse\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash","description":"Branch Target Reuse (BTR), a new Spectre v2 variant, leaks Linux root password hashes in minutes. See CVE-2026-64507 and CVE-2026-64508.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/","og_locale":"en_US","og_type":"article","og_title":"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash","og_description":"Branch Target Reuse (BTR), a new Spectre v2 variant, leaks Linux root password hashes in minutes. See CVE-2026-64507 and CVE-2026-64508.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-30T09:12:24+00:00","article_modified_time":"2026-10-05T06:40:16+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/branch-target-reuse.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash","datePublished":"2026-09-30T09:12:24+00:00","dateModified":"2026-10-05T06:40:16+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/"},"wordCount":1230,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/branch-target-reuse.jpeg?format=webp","articleSection":["Zero-Day","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/","url":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/","name":"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/branch-target-reuse.jpeg?format=webp","datePublished":"2026-09-30T09:12:24+00:00","dateModified":"2026-10-05T06:40:16+00:00","description":"Branch Target Reuse (BTR), a new Spectre v2 variant, leaks Linux root password hashes in minutes. See CVE-2026-64507 and CVE-2026-64508.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/branch-target-reuse.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/branch-target-reuse.jpeg?format=webp","width":1340,"height":700,"caption":"branch target reuse"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/branch-target-reuse-spectre-v2-flaw-leaks-linux-root-hash\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Branch Target Reuse: Spectre v2 Flaw Leaks Linux Root Hash"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2097","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=2097"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2097\/revisions"}],"predecessor-version":[{"id":2143,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/2097\/revisions\/2143"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/2128"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=2097"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=2097"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}