New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
ID: 82c419af-90ae-536b-8fb7-e9ca0b313a7b
STIX ID: report--82c419af-90ae-536b-8fb7-e9ca0b313a7b
Feed Name: Bleeping Computer
**TONTOU (Time-of-Neutralization to Time-of-Use) bypass of Spectre v2 mitigations enables kernel memory disclosure** — Researchers from MIT disclosed an interrupt-injection technique that re-poisons branch predictors after neutralization, allowing unprivileged code to leak kernel secrets (demonstrated on AMD Zen 2 with extraction of /etc/shadow at ~5.47 bytes/s); the attack is a sophisticated proof-of-concept requiring precise interrupt timing and control over unprivileged execution and is reported to be possible on Intel with additional complexity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
