BlackTree Security · Infrastructure · Automation · AI

Researchers Read a Linux Root Hash With Spectre Defences Still On

In a lab demonstration, Branch Target Reuse recovered a Linux root hash in three to five minutes on two recent Intel processors. It began with unprivileged local code and recovered a hash loaded into an su process, not a plaintext password or root access.

The VUSec research matters now because its paper and public repository include an end-to-end Linux cBPF exploit. The sources reviewed do not report malicious exploitation.

Old predictions survived new code

Just-in-time compilers repeatedly create, free and replace executable code. VUSec found that processors can execute the new instructions correctly while retaining an old indirect-branch prediction for the previous code.

The demonstrated attack uses classic BPF filters installed through seccomp, repeated system calls and a cache side channel. It steers transient execution through the stale prediction, then measures the traces left by data that architectural execution should not expose.

The paper reports about eight bytes per second of end-to-end leakage. After the researchers ran su root, the exploit found the su process and recovered its root password hash in an average of three minutes on Raptor Cove and five minutes on Lion Cove.

The broad finding is not a broad exploit

The project’s cross-platform results show stale-prediction behaviour on every tested processor across Intel, AMD and Arm. The complete Linux exploit ran only on the two Intel systems.

Firefox’s SpiderMonkey engine yielded a proof of concept for speculative arbitrary code execution, but not a completed browser exploit. GraalVM exposed the reuse condition, while its normal compilation and garbage collection removed the predictor state before a full chain completed.

Oracle merged code-cache randomisation into GraalVM’s main development branch on 19 August. BlackTree could not confirm the first released GraalVM build containing it. According to the researchers, Mozilla considered predictor-flush mitigations and is prioritising site isolation. No primary Mozilla response or fixed Firefox version was verified.

The fixes target reused BPF memory

Linux addressed the demonstrated path with two linked changes:

  • CVE-2026-64508 adds the BPF mechanism for flushing indirect-branch predictions before reused JIT memory executes. The official advisory identifies classic BPF as the unprivileged attack surface.
  • CVE-2026-64507 enables the x86 response when the BPF JIT and Spectre v2 mitigations are active. Its official advisory says the kernel issues an Indirect Branch Prediction Barrier when appropriate.

Both advisories say the vulnerable code entered upstream Linux 5.18. They list fixes in 6.1.183, 6.6.145, 6.12.97, 6.18.39, 7.1.4 and 7.2, and recommend installing the latest stable kernel rather than cherry-picking individual commits.

Distribution status decides the real patch window

Canonical rates both issues Medium. On 29 September, Ubuntu 26.04 LTS listed its generic kernel as fixed in 7.0.0-31.31, while the 24.04 LTS generic kernel remained vulnerable with work in progress. Administrators should check the exact kernel flavour in Ubuntu’s first record and second record.

Debian lists both issues fixed for Bookworm security linux 6.1.187-1 and linux-6.12 6.12.107-1~deb12u1. Trixie is fixed in 6.12.107-1; its security suite lists 6.12.111-1. Match the installed package against both Debian tracker entries and the companion record.

Shared Linux hosts deserve the first look

Prioritise shared compute, developer platforms and other Linux systems where less-trusted workloads can run locally. Record the running kernel package, then check both CVE-2026-64507 and CVE-2026-64508 against its vendor tracker.

Apply the vendor update, reboot if required and verify that the fixed kernel is running. Constant blinding is not sufficient because VUSec’s second exploit bypassed it. The upstream kernel team discourages unsupported one-off cherry-picks.

The CVEs were assigned in July. The late-September change is the public research and reproducible artifacts, not a new assignment or active campaign. BlackTree’s earlier article on Tontou’s Spectre v2 timing gap covers a different technique and the same operational rule: verify the mitigation protecting the path you expose.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *