New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
AI Summary
Researchers from MIT CSAIL discovered a new side-channel attack technique called INTERRUPT INJECTION that exploits a timing vulnerability in Spectre v2 mitigations on Intel and AMD CPUs. By injecting hardware interrupts at a precise moment between branch predictor sanitization and kernel use, an unprivileged local program can re-poison the predictor and leak kernel memory, including sensitive data like /etc/shadow. The attack bypasses existing Safe-RET protections on AMD Zen 1 through Zen 4 processors and has been demonstrated on Zen 2 with 91.97% accuracy. A patch has been merged into the Linux kernel, but no CVE has been assigned, and Intel considers mitigation unnecessary despite demonstrated mispredictions.
AI-extracted · verify before operational use