New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
Researchers have discovered a new variant of the Spectre v2 speculative execution attack, dubbed "Branch Target Injection" (BTI), that can bypass existing defenses and leak sensitive information from Linux memory.
This attack exploits a vulnerability in how modern processors predict and execute instructions. By manipulating the processor's branch prediction mechanism, attackers can trick it into executing malicious code that leaks data from protected memory regions.
The BTI attack is particularly concerning because it can bypass mitigations that were put in place to protect against earlier Spectre and Meltdown vulnerabilities. This means that even systems that have been patched against previous attacks are still vulnerable to this new threat.
The researchers have demonstrated that the BTI attack can be used to leak kernel memory, which contains highly sensitive information about the operating system and running processes. This could potentially lead to the disclosure of cryptographic keys, passwords, and other confidential data.
While the researchers have developed a proof-of-concept exploit, they have also worked with processor vendors and the Linux kernel community to develop and deploy mitigations. These mitigations involve changes to the processor's microcode and the Linux kernel's memory management.
Users are advised to keep their Linux systems updated with the latest security patches to protect against this new vulnerability.




