TONTOU is an attack on Intel and AMD CPUs that allows bypassing protection against Spectre v2 vulnerabilities.

Researchers from the Massachusetts Institute of Technology have identified the TONTOU (Time-of-Neutralization to Time-of-Use) attack technique, which offers a new way to exploit microarchitectural vulnerabilities in the Spectre v2 class. The vulnerability allows kernel memory contents to be determined when executing an exploit in user space. Code to block exploitation of the vulnerability has been integrated into the kernel. Linux August 5 and included in releases 7.1.7, 6.18.43, 6.12.102, 6.6.149, 6.1.181, 5.15.214 and 5.10.263.

Researchers demonstrated the feasibility of a local, unprivileged user attack to determine the root user's password hash stored in the /etc/shadow file and loaded into memory during system authentication. The researchers successfully leaked data from kernel memory at a throughput of 5.47 bytes per second and an accuracy of 91.97%. Of 10 test runs of the exploit, which lasted an average of 18 minutes, half of the time they successfully detected the presence of the /etc/shadow file in memory and extracted its contents.

The exploit was demonstrated on systems with AMD processors and can be used on AMD CPUs of the Zen 1-4 families. The attack is also feasible on Intel systems, but exploitation is more complex. To protect against return stack overflows and block the SRSO (Speculative Return Stack Overflow) vulnerability, AMD processors employ the Safe-RET protection mechanism, which clears the branch prediction buffer after each use and narrows the attack window to two instructions executed within a few tens of nanoseconds.

To bypass this protection and expand the attack window, a CPU slowdown technique was implemented, allowing for interrupt substitution at the right moment to redirect execution flow within the kernel and use an interrupt handler to corrupt entries in the branch prediction buffer. To exploit the SRSO vulnerability, an attacker can create conditions where the branch prediction unit speculatively executes a large number of incorrectly predicted CALL calls, enough to overflow the return address stack and overwrite correctly predicted return points located at the beginning of the stack. As a result, the initial stack elements can be overwritten with values ​​chosen by the attacker, which subsequently leads to the use of these replaced values ​​during speculative execution of a RET instruction in the context of another process.

The processor will determine that the branch prediction was incorrect and roll back the operation, but the data processed during speculative execution will remain in the cache and microarchitectural buffers. If the erroneously executed block accesses memory, its speculative execution will also result in the data read from memory remaining in the shared cache. To retrieve information from the cache, one can use a method for determining cache contents based on analysis of changes in access times for cached and non-cached data.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster