#5
BleepingComputer
general
August 06, 2026 at 18:03 UTC
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
By Ionut Ilascu
AI Summary
MIT CSAIL researchers Danïel Trujillo and Mengjia Yan demonstrated TONTOU (also named INTERRUPT INJECTION), a new attack that bypasses all default Spectre v2 mitigations on Linux 6.14 running AMD Zen 2 CPUs by timing a hardware interrupt to land between branch predictor sanitization and kernel use, re-poisoning the predictor after defenses have run. The technique enables an unprivileged Linux process to leak secrets including password hashes, undermining the assumption that current Spectre v2 patches provide adequate protection on Intel and AMD hardware.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →