New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

Summary

Researchers have discovered a new attack called "INTERRUPT INJECTION" that can bypass Spectre v2 defenses on Intel and AMD CPUs. This attack exploits a timing vulnerability where an unprivileged Linux program can re-poison the processor's branch predictor after the defense mechanism has run.

IFF Assessment

FOE

This vulnerability allows attackers to bypass existing security mitigations, posing a direct threat to system integrity and confidential data.

Severity

8.8 High (AI Estimated)

This score reflects a high severity due to the attack's ability to bypass established defenses (Spectre v2 mitigations) on widely used CPUs (Intel and AMD). It allows for unauthorized access to information, potentially leading to significant data compromise. The attack vector is local, but the impact on confidentiality is critical.

Defender Context

This research highlights a significant flaw in CPU-level security mitigations, indicating that even with Spectre v2 defenses enabled, systems remain vulnerable. Defenders should stay updated on potential exploits targeting branch predictors and be prepared for new patching or hardware-level solutions from CPU manufacturers.

Read Full Story →