Spectre-v2 BTR attack leaks Linux kernel memory via cBPF
Researchers from VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a Spectre-v2 attack that abuses stale CPU branch predictions to leak Linux kernel memory. A classic BPF exploit on Intel CPUs reads about 8 bytes per second and extracted the root password hash from the su process. Kernel fixes are tracked as CVE-2026-64507 and CVE-2026-64508.
- BTR abuses stale CPU branch predictions after memory reuse
- cBPF exploit on Intel reads ~8 bytes/s and extracted the su root password hash
- Disabling unprivileged eBPF does not close the vector: cBPF is used by seccomp, Docker and Chrome
- CPU behavior seen on Intel, AMD and Arm, but the full exploit targets Intel
Read next
Security