New Spectre v2 attack impacts Linux systems on Intel CPUs
ID: 1cb2461f-d930-5660-9e2c-d949a81613d0
STIX ID: report--1cb2461f-d930-5660-9e2c-d949a81613d0
Feed Name: Bleeping Computer
Researchers from VUSec disclosed a new Spectre v2 variant (CVE-2024-2201) that leverages Branch History Injection to leak privileged memory on many Intel processors running Linux. They released InSpectreGadget, a symbolic-execution tool that identifies exploitable kernel gadgets and demonstrated a native exploit; vendors and distributions are issuing and evaluating mitigations (disabling unprivileged eBPF, enabling IBT/eIBRS, LFENCE insertion, etc.), but existing mitigations may be insufficient and configurations vary across platforms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
