Technologies
Back
Cybersecurity & Privacy

Security Week 2641: A New Spectre-v2 Attack

Habr
Advertisement468 × 90
Security Week 2641: A New Spectre-v2 Attack

Researchers from the Netherlands and Italy have unveiled a new attack that expands the Spectre-v2 class of vulnerabilities. Unlike the original 2018 attack, which relied on branch target injection, this new method utilizes Branch Target Reuse within the processor's branch prediction system. The vulnerability is triggered by interactions with JIT compilers, a scenario previously considered impractical. The study successfully demonstrated the extraction of secret data via the cBPF JIT compiler in the Linux kernel. Experts also analyzed potential risks for the SpiderMonkey (Firefox) and GraalVM compilers. This research highlights the need to re-evaluate security approaches for branch prediction mechanisms in modern processors, as the combination of JIT compilation features and hardware optimizations creates new vectors for side-channel attacks.

This is a summary. Read the full article at the original source:

Habr
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250