SendTech Times
Analysis
MARKET SIGNAL:

TONTOU CPU Attack Tests Spectre Defenses On Linux Systems

Newsroom brief

Researchers showed a Time-of-Neutralization to Time-of-Use technique that can repollute branch prediction state after Spectre v2 mitigations and leak Linux kernel data in lab tests.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: BleepingComputer
TONTOU CPU Attack Tests Spectre Defenses On Linux Systems
Image source: BleepingComputer

A new CPU side-channel attack can bypass recent Spectre v2 mitigations on Linux systems and leak privileged data, including password hashes, after an attacker gains the ability to run unprivileged code on a target machine.

BleepingComputer reported that Daniël Trujillo, a PhD student, and associate professor Mengjia Yan of MIT CSAIL found a way to exploit the short interval between the moment a branch predictor is neutralized and the moment a protected victim branch uses it.

The researchers call that interval Time-of-Neutralization to Time-of-Use, or TONTOU.

Spectre v2, also known as Branch Target Injection, abuses a processor's indirect branch predictor so the CPU speculatively executes instructions along an attacker-influenced path.

Intel and AMD mitigations such as Intel eIBRS and AMD Safe RET are designed to sanitize or isolate branch-predictor state before sensitive control flow executes.

TONTOU targets the assumption that the cleaned state cannot be usefully repolluted before the victim branch runs.

The researchers introduced a primitive that lets an attacker poison CPU state after neutralization but before use.

"An attacker without any special access to read arbitrary memory from the system, including sensitive data such as hashed passwords," Trujillo told BleepingComputer.

The attack uses interrupt injection.

Unprivileged user programs can schedule timer interrupts during kernel execution, causing the kernel to enter an interrupt handler.

That handler can then be used to poison microarchitectural state inside the post-neutralization window.

The researchers found that interrupts during that window can poison the processor's indirect branch predictor and enable attacks against all types of indirect branches.

Exploitation still requires several difficult steps: redirecting kernel control flow, aligning interrupts precisely with the post-neutralization window, and poisoning the predictor entry tied to the target indirect branch.

In tests on an AMD Zen 2 system running Linux 6.14.0-37-generic with 16GB of RAM, Trujillo and Yan demonstrated arbitrary kernel memory leakage at 5.47 bytes per second with 91.97% accuracy.

The leaked data included contents of /etc/shadow, the Linux file that stores password hashes.

Across 10 runs, the attack located and extracted the file in five cases.

Each attempt took an average of 18 minutes.

The attack was also tested on Intel processors, though the researchers found that additional software requirements made exploitation more complex.

On AMD systems, they combined interrupt injection with Inception, a previously disclosed attack that Trujillo helped develop, because passive Return Stack Buffer pollution was less reliable.

AMD published an advisory saying the interrupt-injection issue "appears to be associated" with how Linux implements the Safe RET mitigation against possible information disclosure attacks.

Trujillo and Yan presented the findings at Black Hat USA.

They are also scheduled to share details at USENIX Security 2026, which runs from October 27 to October 29.

Share this article
inXf

Related articles

More
CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda
Cybersecurity

CISA Android and Linux Warnings Put Patch Timing Back on the Security Agenda

CISA added exploited Android and Linux vulnerabilities to its Known Exploited Vulnerabilities catalog. The Android flaw affects Android 14 through 16, while the Linux issue centers on older kernel branches and cgroups v1 container environments. The immediate test is whether agencies and infrastructure operators apply vendor updates or mitigations by CISA's June 5 deadline.

Caliptra Hardware Trust Work Shifts From Standard To Deployment
Cybersecurity

Caliptra Hardware Trust Work Shifts From Standard To Deployment

A Semiconductor Engineering article says Caliptra can align hardware trust for data-center devices, but production systems still need lifecycle controls, attestation links, cryptographic agility and SoC-wide security orchestration.

Markey Bill Would Shift AI Hack Reviews To Federal Board
Cybersecurity

Markey Bill Would Shift AI Hack Reviews To Federal Board

Sen. Ed Markey’s bill would create a Cybersecurity and AI Board of Investigations for AI agent-led hacks, with subpoena authority and a mandate covering federal systems and critical infrastructure.

Google Freezes OSS Bug Bounty Reports After AI Submission Flood
Cybersecurity

Google Freezes OSS Bug Bounty Reports After AI Submission Flood

Google has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.

IBM Buys Logiq to Deepen UK Cybersecurity Work in Regulated Sectors
Politics

IBM Buys Logiq to Deepen UK Cybersecurity Work in Regulated Sectors

IBM UK has acquired Logiq Consulting, adding NCSC-assured cybersecurity, Secure by Design and sovereign collaboration expertise for defence, critical infrastructure and public-sector clients.

Hitachi Tests Claude for Critical Infrastructure AI
AI

Hitachi Tests Claude for Critical Infrastructure AI

Hitachi partnered with Anthropic to strengthen Lumada 3.0 and bring Claude into mission-critical infrastructure settings. The plan covers HMAX solutions, cybersecurity work, internal deployment to about 290,000 employees and training for around 100,000 AI professionals. The main test is whether safety-focused generative AI can become reliable enough for regulated operational workflows.

Authorizer Filters AI File Access Through App Login Rules
Cloud & Data Centers

Authorizer Filters AI File Access Through App Login Rules

Authorizer combines self-hosted authentication with OpenFGA permissions and a local MCP interface, giving app teams a way to filter AI document access before vector search results are scored.

Keep Reading

More Stories

Latest
Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.Schneider Electric Lines Up $22.6 Billion PTC DealAIOct 5, 2026Schneider Electric Lines Up $22.6 Billion PTC DealSchneider Electric plans to buy PTC in a cash transaction valuing the US engineering software provider’s equity at about $22.6 billion, adding product-lifecycle software to its industrial AI push.Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueCapital & PolicyOct 5, 2026Aggarwal Pledges Ola Electric Stake To Fund ₹1,000 Cr Rights IssueOla Electric founder Bhavish Aggarwal pledged 20 Cr shares to finance his participation in a rights issue that forms part of a larger ₹1,500 Cr fundraising plan.Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseAIOct 5, 2026Natrona Schools AI Review Puts Student Privacy Ahead Of Classroom Tool UseNatrona County trustees questioned whether teacher AI tools expose student data, even as existing district rules already ban unauthorized generative AI use by students.AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersChips & SemiconductorsOct 5, 2026AMD Prices 256-Core EPYC 9996 At $14,904 For Server BuyersTechRadar reports that AMD’s 6th Gen EPYC 9006 “Venice” lineup includes a 256-core EPYC 9996 with 512 threads, 1GB of L3 cache, a 600W default power rating and a $14,904 list price for 1,000-unit orders.