Home / Aug 07, 2026 / Story
0
#5 BleepingComputer general August 06, 2026 at 18:03 UTC

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

By Ionut Ilascu

AI Summary

MIT CSAIL researchers Danïel Trujillo and Mengjia Yan demonstrated TONTOU (also named INTERRUPT INJECTION), a new attack that bypasses all default Spectre v2 mitigations on Linux 6.14 running AMD Zen 2 CPUs by timing a hardware interrupt to land between branch predictor sanitization and kernel use, re-poisoning the predictor after defenses have run. The technique enables an unprivileged Linux process to leak secrets including password hashes, undermining the assumption that current Spectre v2 patches provide adequate protection on Intel and AMD hardware.

Relevance score: 87.0/100

# More from August 07