New TONTOU CPU Attack Bypasses Spectre v2 Mitigations, Leaks Linux Password Hashes
Researchers have discovered a new CPU attack method, named TONTOU, that bypasses existing Spectre v2 mitigations on AMD and Intel processors. This attack exploits a gap in the neutralization-based mitigations, allowing attackers to leak sensitive data, such as Linux password hashes. The method involves re-poisoning the CPU's state after the branch predictor is cleaned but before it is used, enabling speculative execution of attacker-chosen code paths. The attack was demonstrated on an AMD Zen 2 system, successfully leaking kernel memory at a rate of 5.47 bytes per second with high accuracy.