Toggle light / dark theme

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers found a way to bypass recent mitigations for Spectre v2 speculative execution side-channel attacks and developed an exploit to leak secrets from Linux machines.

The method works against Spectre v2 defenses on AMD and Intel processors that rely on sanitizing or isolating branch predictors, which researchers generically refer to as neutralization-based mitigations.

Spectre v2 is also known as Branch Target Injection (BTI) and is a variant of the Spectre class of vulnerabilities.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */