Skip to content
cve — cve-2026-64507

grep -rl "CVE-2026-64507" ./articles

CVE-2026-64507

VUSEC's Branch Target Reuse attack uses a gap nobody closed: when a JIT engine throws away compiled code and writes new code in the same place, the processor updates what is there but keeps its old prediction of where the jump goes. On a fully patched Intel machine with default mitigations, their Linux exploit pulls the root password hash out of kernel memory at eight bytes a second.

1 article — 2026-10-01

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

The CPU forgets the code and remembers where it jumped. That is enough to read the root hash

2026-10-01Security

VUSEC's Branch Target Reuse attack uses a gap nobody closed: when a JIT engine throws away compiled code and writes new code in the same place, the processor updates what is there but keeps its old prediction of where the jump goes. On a fully patched Intel machine with default mitigations, their Linux exploit pulls the root password hash out of kernel memory at eight bytes a second.

../cve — every identifier we have covered