chiprook
← Security
SecurityOctober 2, 2026, 05:34

Spectre-v2 BTR attack leaks Linux kernel memory via cBPF

Researchers from VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a Spectre-v2 attack that abuses stale CPU branch predictions to leak Linux kernel memory. A classic BPF exploit on Intel CPUs reads about 8 bytes per second and extracted the root password hash from the su process. Kernel fixes are tracked as CVE-2026-64507 and CVE-2026-64508.

Spectre-v2 BTR attack leaks Linux kernel memory via cBPF
#Linux#Intel#Firefox#GraalVM
Read next
Security

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

Security

CISA Adds Linux Kernel CVE-2026-53266 to Known Exploited Vulnerabilities Catalog

Security

ZcopyReaper: A Local Privilege Escalation in the Linux Kernel RDS Path

Security

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root