{"rewrite":{"id":"r_4ef982e4e21e14dd3b9f0967","clusterId":"c_64dcbc8860888a4067529e2a","slug":"tontou-attack-bypasses-spectre-v2-mitigations-to-leak-linux-password-hashes","model":"deepseek-v4-flash:free","headline":"TONTOU Attack Bypasses Spectre v2 Mitigations to Leak Linux Password Hashes","summary":"MIT CSAIL researchers presented TONTOU, an attack that bypasses Spectre v2 mitigations by re-injecting attacker-controlled data into the branch predictor after it has been neutralized. The team demonstrated reading Linux kernel memory and obtaining /etc/shadow contents. Tests on Intel and AMD CPUs found the method worked on some architectures but not others.","whyItMatters":"The technique exploits a time gap between when mitigations clear branch prediction state and when that state is actually used, showing that neutralization-based defenses can be re-contaminated just before a protected branch executes.","webCardHtml":"\u003cp\u003eSpectre v2 mitigations rely on clearing or isolating the branch prediction state that attackers can poison. MIT CSAIL found a gap between the moment that neutralization completes and the moment the branch predictor is actually consulted, and built an attack to fill it.\u003c/p\u003e\u003cp\u003eTONTOU, short for Time-of-Neutralization to Time-of-Use, works in four steps. The kernel neutralizes the branch predictor, the attacker guides the victim toward a training gadget, that gadget re-contaminates the predictor, and the tainted state is used for a protected branch that leaks secrets through a disclosure gadget. The attack uses interrupt injection, triggered by a user-level timer, to land an interrupt during kernel processing at a useful moment.\u003c/p\u003e\u003cp\u003eThe researchers tested Intel Cascade Lake Refresh and Arrow Lake, plus AMD Zen 2 and Zen 4. They retrained some branch prediction mechanisms on Intel, and on Zen 2 they bypassed the Linux mitigation Safe RET. On Zen 4, the same method produced no confirmed misprediction.\u003c/p\u003e","blueskyPost":"TONTOU re-injects data into the branch predictor after Spectre v2 mitigations clear it. The attack's architecture dependence means patching is uneven across Intel and AMD.","twitterPost":"TONTOU works on some Intel and AMD CPUs but not others, so Spectre v2 fixes cannot be uniform.","threadsPost":"TONTOU shows that Spectre v2 mitigations are not a single fix. By re-injecting data after the branch predictor is neutralized, MIT CSAIL's attack reads /etc/shadow on some Intel and AMD chips, while others stay safe. That split forces per-architecture patching.","newsletterBlurb":"MIT CSAIL researchers presented TONTOU, a Spectre v2 bypass that re-contaminates the branch predictor after mitigations clear it. The attack read Linux kernel memory and /etc/shadow. It succeeded on Intel Cascade Lake Refresh and Arrow Lake and AMD Zen 2, but not on Zen 4.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260807-tontou-spectre-v2/\",\"title\":\"New attack 'TONTOU' bypassing Spectre v2 mitigations demonstrated to leak Linux password hashes\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":4627,"outputTokens":651,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1786401491,"createdAt":"2026-08-10T22:29:15.000Z","publishedAt":"2026-08-10T22:31:44.000Z","updatedAt":"2026-08-10T22:29:15.000Z"},"cluster":{"id":"c_64dcbc8860888a4067529e2a","canonicalTitle":"Spectre v2対策を突破する新攻撃「TONTOU」が登場、Linuxのパスワードハッシュ漏えいを実証","representativeArticleId":"a_dc06c6165f58e3d3df97e8a1","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-08-07T09:15:00.000Z","lastSeenAt":"2026-08-07T09:15:00.000Z","updatedAt":"2026-08-10T22:31:44.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260807-tontou-spectre-v2/","title":"Spectre v2対策を突破する新攻撃「TONTOU」が登場、Linuxのパスワードハッシュ漏えいを実証"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
