{"id":2252,"date":"2026-08-06T17:34:31","date_gmt":"2026-08-06T17:34:31","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2252"},"modified":"2026-08-06T17:34:31","modified_gmt":"2026-08-06T17:34:31","slug":"new-interrupt-injection-attack-can-bypass-spectre-v2-defenses-on-intel-and-amd-cpus","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2252","title":{"rendered":"New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOSra_DOAu8v1CYXAo4z3cStSiHsuM6iF5vjHKmq0Q4kXMtGQ3n5EBjJoLNRzEFgW6xs6-GuSP0tUAX-EPYRHaDQQNHuz-8xSFbp__BShjMumlZdcwuZkl3GkVebYtWoYuqfgbyt-yKGo1OAal-ElVBKnRaiwjQKO7hgynkFx06IVH7Ipm43p4wc6NR9Y\/s1700-e365\/TONTOU.gif\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run.<\/p>\n<p>MIT CSAIL researchers<strong> Dani\u00ebl Trujillo<\/strong> and <strong>Mengjia Yan<\/strong> named the technique <strong>INTERRUPT INJECTION<\/strong>. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on, their exploit leaked arbitrary kernel memory at 5.47 bytes per second with 91.97% accuracy, enough to locate and read \/etc\/shadow, which stores the system&#8217;s password hashes, in five of ten attempts.<\/p>\n<p>It needs no privileges, only local code execution, so the risk sits on shared systems running an affected processor.<\/p>\n<p>The pair <a href=\"https:\/\/www.csail.mit.edu\/news\/new-attack-slips-past-latest-defenses-built-your-computers-processor\" target=\"_blank\">disclosed<\/a> to AMD and Intel on February 5. AMD told them it plans a kernel patch; MIT says one has since shipped and arrives in a normal operating system update.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>A fix is in the Linux kernel. The commit, <a href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=f5fdd6665ac4d8528ed1c9242cb1cf7a7f5bdb0e\" target=\"_blank\">\u00abx86\/bugs: Make Safe-RET robust against interrupt injection\u00bb<\/a>, is dated June 2 and was written by Borislav Petkov and co-developed with David Kaplan, both AMD engineers. It describes the attack in the same terms the researchers do: injecting interrupts while Safe-RET runs \u00abcan neutralize the safe return sequence, potentially leading to data leakage through speculative execution.\u00bb<\/p>\n<p>The patch fixes up register state as though the Safe-RET sequence had completed, and avoids executing a RET instruction after the interrupt returns. That is one of the two routes the paper proposed.<\/p>\n<p>AMD published a bulletin on August 6, <a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7061.html\" target=\"_blank\">AMD-SB-7061<\/a>, titled \u00abSafe RET Interrupt Vulnerability,\u00bb naming Zen 1 through Zen 4 processors as affected. Its summary says an attacker running code on an affected system \u00abcould inject an interrupt at a precise moment to disrupt Safe RET,\u00bb which \u00abcould potentially weaken that protection and may result in information disclosure.\u00bb AMD adds that the issue \u00abappears to be associated with the Linux implementation of the Safe RET mitigation.\u00bb<\/p>\n<p>The bulletin credits Trujillo and says the behavior was demonstrated on Zen 1 and Zen 2, with Zen 3 and Zen 4 suggested but not demonstrated. The paper reports AMD testing on Zen 2 and Zen 4 only. The section headed \u00abAffected Products and Mitigation\u00bb lists processors and nothing else: no patch reference, no kernel version, and no CVE.<\/p>\n<p>According to the <a href=\"https:\/\/people.csail.mit.edu\/mengjia\/data\/2026.USENIX.TONTOU.pdf\" target=\"_blank\">paper<\/a> the researchers shared with The Hacker News, Intel does not consider a mitigation necessary.<\/p>\n<p>Neither AMD&#8217;s bulletin nor MIT&#8217;s announcement points to the kernel commit. Without a CVE or a named kernel release, an administrator has to know the commit subject to check whether a given machine carries the fix.<\/p>\n<p>The kernel reports SRSO status at \/sys\/devices\/system\/cpu\/vulnerabilities\/spec_rstack_overflow, and the <a href=\"https:\/\/kernel.org\/doc\/html\/latest\/admin-guide\/hw-vuln\/srso.html\" target=\"_blank\">documentation defining that file&#8217;s values<\/a> made no mention of interrupts when The Hacker News checked it on August 6.<\/p>\n<p>The Hacker News has contacted AMD, Intel, and Arm for comment and will update this story with any response.<\/p>\n<p>Each of these defenses sanitizes or isolates branch predictor state so an attacker&#8217;s earlier training cannot steer a kernel branch. Intel does it on kernel entry, with <a href=\"https:\/\/thehackernews.com\/2025\/05\/researchers-expose-new-intel-cpu-flaws.html\" target=\"_blank\">eIBRS and, depending on the processor, either a branch history buffer clearing loop or the BHI_DIS_S control. AMD does it immediately before each kernel return, with saferet.<\/p>\n<p>All of them assume nothing hostile runs in between. Trujillo and Yan call the class TONTOU, for Time-of-Neutralization to Time-of-Use, after the TOCTOU races familiar from software. Interrupts break that assumption, because they fire almost anywhere and Linux lets any user schedule them with nanosecond granularity.<\/p>\n<p>If interrupt handling can execute between neutralization and use, the interrupt-return path is part of the Spectre v2 defense even when the mitigation was designed around kernel entry or return.<\/p>\n<p>On Zen 2 that window is two instructions, six bytes. The researchers widened their odds by evicting those bytes from L1 and L2 cache using a sibling hyperthread, slowing them down, and by picking the write syscall, which left them controlling two registers.<\/p>\n<p>Interrupts landed inside the window 5% to 12% of the time, and around 2% with those registers under attacker control. Once inside, the handler itself became the training gadget, armed with <a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7005.html\" target=\"_blank\">Inception<\/a> (CVE-2023-20569) to fill the return stack buffer with an attacker-chosen target. Inception is the 2023 AMD flaw saferet exists to stop.<\/p>\n<p>Mispredictions turned up in kernel code on three of the four machines tested, at success rates of 0.75% on Zen 2, 0.22% on Intel Arrow Lake, and 0.037% on Cascade Lake Refresh. Zen 4 produced none in that test, and no end-to-end leak was demonstrated on Intel, where the attacker would also need a usable disclosure gadget already in the kernel.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The researchers do not treat that as a barrier. Mispredictions are \u00aba necessary but not sufficient condition for a Spectre attack,\u00bb they told The Hacker News, and because prior work has already shown disclosure gadgets exist in kernels, \u00abwe believe an end-to-end attack is possible on Intel as well by combining our Interrupt Injection primitive with this work.\u00bb<\/p>\n<p>Intel paid a discretionary bug bounty bonus but, per the paper, \u00abdoes not consider mitigation to be required,\u00bb saying exploitability \u00abdepends on many factors\u00bb and that the technique is covered by <a href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/branch-history-injection.html\" target=\"_blank\">existing guidance<\/a>. The Hacker News reviewed that guidance, INTEL-SA-00598, in its current version last updated in May 2025, and found no mention of interrupts anywhere in it.<\/p>\n<p>The pair presented the work at <a href=\"https:\/\/blackhat.com\/us-26\/briefings\/schedule\/#breaking-recently-deployed-spectre-v2-mitigations-a-novel-attack-primitive-53157\" target=\"_blank\">Black Hat USA<\/a> today, and the paper is due at <a href=\"https:\/\/www.usenix.org\/conference\/usenixsecurity26\/presentation\/trujillo\" target=\"_blank\">USENIX Security<\/a> in Baltimore next week. As of August 6, the artifact repository named in it was not yet public.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2253,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2378,220,394,2928,899,525,2377,2926,2927],"class_list":["post-2252","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-amd","tag-attack","tag-bypass","tag-cpus","tag-defenses","tag-injection","tag-intel","tag-interrupt","tag-spectre"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2252","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2252"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2252\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2253"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2252"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2252"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2252"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}