New CPU Flaw BTR Targets Intel, AMD, ARM via JIT

A group of researchers from the Free University of Amsterdam has developed a new attack method BTR (Branch Target Reuse), belonging to the Spectre-v2 class. This attack allows bypassing memory isolation mechanisms on systems with Intel processors, AMD, and ARM. The initiation of memory leaks during speculative execution of instructions in the BTR attack is achieved through manipulations with JIT compilers. The researchers have assessed the feasibility of carrying out an attack through the JIT engines cBPF in the Linux kernel, Oracle GraalVM, and SpiderMonkey in Firefox.

To confirm the practicality of the attack, two exploits have been prepared that enable the extraction of the root user password hash loaded from the /etc/shadow file into memory after starting su utilities. The attack manipulates the cBPF (Classic Berkeley Packet Filter) engine provided in the Linux kernel, which is also utilized in the seccomp mechanism to limit access to system calls. These exploits have been proven to be effective on Ubuntu 24.04 with the 6.14.0-27-generic kernel in the default configuration. On a computer with an Intel CPU, the leakage rate is 8 bytes per second, sufficient to retrieve a password hash from memory within 3-5 minutes.

Spectre-v2 attacks for leaking data involve substituting values in the Branch Target Buffer or Branch History Buffer, used for predicting the next branch operation. By manipulating the branch history, conditions are set for inaccurate branch prediction during the speculative execution of instructions. The attacker aims to ensure that when performing a speculative branch operation, the address to jump to is taken from the desired memory area. After executing a speculative transition, the transition address read from memory remains in the processor cache (with the data needed by the attacker obtained from memory under a disguised address). To extract information from the cache, one method involves determining the cache contents based on analyzing changes in access time to cached and uncached data.

/Reports, release notes, official announcements.