Branch Target Reuse leaks root hashes on patched Intel CPUs

Branch Target Reuse leaks root hashes on patched Intel CPUs
Six years after Spectre, chip makers still haven't learned. A new variant — Branch Target Reuse (BTR) — slips past hardened kernels and JIT compilers to spill root password hashes on patched Intel Linux systems — in minutes, no malware required. VU Amsterdam and Sant'Anna researchers demonstrated full end-to-end exploits at ~5.7 KB/sec on Raptor Cove. BTR targets stale Branch Target Buffer entries in reused JIT machine code. Two CVEs (2026-64507/64508) are out; Linux, GraalVM, and Firefox shipped countermeasures. The cost? A real performance tax on JIT-heavy workloads. The pattern repeats: discover microarchitectural flaw → patch with a performance hit → declare victory. Retbleed was supposed to be the wake-up call. BTR shows the architecture never got the memo.

Six years after Spectre named and shamed modern CPUs for leaking secrets, you'd think chip makers and software vendors would have learned. Apparently not. A fresh variant — dubbed Branch Target Reuse (BTR) — has thumbed its nose at every mitigation in the book, slipping past hardened kernels and JIT compilers to spill root password hashes on patched Intel Linux systems in minutes. Researchers from VU Amsterdam and Scuola Superiore Sant'Anna demonstrated full end-to-end exploits.

Here's the uncomfortable part: nothing about this attack requires malware, exotic hardware, or even your machine being compromised first. BTR is the first practical in-place Spectre v2 attack targeting just-in-time compilers. It works by exploiting stale entries in the CPU's Branch Target Buffer (BTB) — the hardware structure that guesses where a branch will jump. When a JIT engine reuses existing machine-code bytes at different memory offsets, the CPU's prediction goes stale, mispredicts, and leaks privileged data through cache timing.

So What Actually Leaks?

  • Kernel root password hashes — exfiltrated directly from the kernel via reused JIT code in GraalVM.
  • Privileged data via machine-code offsets — the attack crafts the usable bytes out of whatever code is already loaded; no injected payload required.
  • Leakage rates: ~5.7 KB/sec on Intel's Raptor Cove, ~5.4 KB/sec on Lion Cove. Slow, sure — but a root hash only takes a few seconds of reading, and that's all it takes.

Two CVEs are now on the books: CVE-2026-64507 and CVE-2026-64508, assigned by vendors scrambling to respond. Linux kernel maintainers merged mitigations, and Oracle and Mozilla shipped their own defenses — GraalVM and Firefox both bolted on custom countermeasures.

The Mitigation Circus

And here's where the cynicism is earned. The recommended fixes read like a wish list that punishes everyone equally:

  • CPU-wide invalidation of branch predictors during function reuse or code caching — which quietly tanks performance on workloads that lean on JIT compilation.
  • Hardware-level branch predictor reset on every function-call exit — a sledgehammer for a nail that should have been reseated years ago.

Translation: to stay patched, you accept a measurable performance tax, and you get it in every future compiler, browser, and kernel update. There is no "free lunch here" on Intel silicon made in the last several generations. Notably, this is the second time in recent years that Intel has conceded the arbitrary-memory leak at roughly this same rate — Branch Privilege Injection (CVE-2024-45332) leaked at 5.6 KiB/s since Coffee Lake Refresh, and its "fix" cost up to 2.7% overhead via microcode. BTR just found a cheaper way in.

The Bigger, Awkward Question

Why, after 2018's Spectre meltdown, did branch-prediction hardware ship for years with stale-BTB behavior that was this trivially weaponizable? The street answer, meanwhile, is embarrassingly on-brand. Just weeks before BTR came out, Linux maintainers were still sorting out the latest quarterly installment of the microarchitectural whack-a-mole. Only days earlier, attackers used the LoongLeak flaw against ffmpeg on LoongSoN 3A6000 CPUs to pull partial /etc/shadow entries off shared L1 caches — a textbook demonstration that even "different" architectures ship the same class of speculative-side-channel sins in targeted form.

And the speculative-side-channel theater isn't even the only cirque in town. Even as BTR was being disclosed, threat actors were busy elsewhere in the ecosystem: in late September, Russian-origin actors handed out a 9.8-CVSS unauth RCE in Langflow (CVE-2026-0768) — 360+ UK-based exploitation attempts inside a week, 50+ canary detections in a single morning, root-level code execution stealing OpenAI, AWS, and Langflow secrets. Because when the AI-low-code boom meets hardware that still lies about its predictions, the "secure" software stack was never really holding the line either.

So yes: the pattern is now familiar. Discover devastating microarchitectural flaw → patch with a performance hit → declare victory → repeat. BTR isn't even exotic — it's the same hardware lying, just with a new accent. Retbleed (CVE-2022-29900/29901) took months and ~14–39% overhead to lock down, and it was supposed to be the wake-up call that put stale-branch hardware on notice. BTR shows the architecture never got the memo.

The honest forecast is longer-term: expect hardware-level fixes that force BTB invalidation on function boundaries, expect JIT engines to grow address-space-layout-aware code placement (GraalVM is already randomizing code-cache locations; the Linux kernel added IBPB on cBPF regions), and expect the performance gap between "secure" and "fast" to keep widening. The root-hash leak closes, but the architectural bill for Spectre keeps coming due — and we're all paying the interest. Wearily, and repeatedly.