New version of Specter v2 vulnerability discovered in Intel, AMD and Arm processors – it could expose passwords and other data

New version of Specter v2 vulnerability discovered in Intel, AMD and Arm processors – it could expose passwords and other data

Researchers from the Netherlands and Italy Found A new Specter v2 class vulnerability exists in modern processors – it affects systems using Intel, AMD and Arm chips. Branch target reuse (BTR) attacks target the operating system core, the browser, and the just-in-time JIT compiler used at execution time.

    Image source: Boitumelo/unsplash.com

Image source: Boitumelo/unsplash.com

An attacker who can execute code on a target machine can use BTR to steal sensitive data, such as password hashes in memory. Although researchers have yet to create a full-fledged exploit for the browser, attacks from malicious web pages are theoretically possible. BTR attacks are possible because of the way processors handle code that changes execution time: by restoring the architectural consistency of the code after self-modification, they can retain records of stale indirect branch predictions. In a JIT engine, such stale predictions can outlive the code they were written and can be reused when new code is written to the same address. effective “Speculative execution after memory free”: Speculative execution is directed to new code using old offsets.

Researchers analyzed the Linux cBPF subsystem, the Oracle GraalVM runtime, and Firefox’s SpiderMonkey engine for JavaScript and WebAssembly; and developed two mature exploits targeting the Linux core. They use the classic BPF mechanism – cBPF. The modern eBPF JIT compiler is accessible only to privileged users, while the previous cBPF functionality was more limited but also accessible to unprivileged programs. This compiler runs the Seccomp mechanism, filtering sockets as well as Docker and Chrome packets. On modern Intel processors, this vulnerability allows you to read arbitrary data from memory, bypassing all active protection mechanisms. Even with a read speed of 8 bytes/second, by correctly following the pointer chain, you can obtain sensitive information – researchers were able to read the hash value of the root password after it was loaded into memory.

Photo credit: Kevin Horvat/unsplash.com

For Firefox, the attack is launched via a malicious website that executes JavaScript code in the user’s browser. Mozilla developers have not yet completed the deployment of site isolation, so the contents of all tags could end up in the same address space as the attacker’s code, and all data would be vulnerable. During the experimental implementation of the attack, it turned out that in the SpiderMonkey engine on Intel processors, outdated branch records are stored for a long time and can be reused – the data leakage rate can reach tens of bytes per second, but a mature exploit for browsers has not yet been developed.

In GraalVM, BTR attacks allow an attacker to speculatively bypass the memory masking mechanism designed to protect the runtime from Specter vulnerabilities. The researchers were able to reuse memory addresses, although GraalVM’s own code compilation and garbage collection processes removed branch records before they could be used – but this was a limitation “Not at all”the researchers said.

Software developers acknowledged the study’s findings. Threats can be eliminated programmatically, such as using indirect branch prediction barriers (IBPB). The Linux kernel implements a protection mechanism for the x86 architecture – cBPF will run IBPB whenever it is allocated to a memory area previously used to execute BPF code. Oracle deployed protections and Mozilla decided to spend more time implementing site isolation.

Control flow protection hardware such as IBT on x86 and BTI on Arm complicates exploitation of this vulnerability but does not completely eliminate the threat. Older Intel processors can still speculatively execute instructions before the IBT checks are finally exhausted, creating windows that use the BTR. This behavior disappears only in the Lion Cove architecture (Core Ultra 200 series Arrow Lake and Lunar Lake chips). But even if the processor does not “override” the IBT mechanism, the protection can be bypassed if the constant masking method is disabled.

AMD noted that no new vulnerabilities were discovered in the company’s chips and that existing protection recommendations against Specter v2-type attacks were used to eliminate the BTR method described; Intel and Arm have not yet commented.

If you find an error, select it with your mouse and press CTRL+ENTER.

Exit mobile version