• Sources: coverage, AMD assessment coverage, discussion
  • Summary: MIT CSAIL researchers presented at Black Hat USA a technique that injects timer interrupts into the gap between branch predictor neutralization and use, defeating eIBRS on Intel and Safe RET on AMD. On an AMD Zen 2 Linux host they read arbitrary kernel memory at 5.47 bytes per second with 91.97 percent accuracy and recovered /etc/shadow in five of ten runs. AMD's bulletin, quoted by Phoronix, places the flaw in the Linux implementation of Safe RET rather than in the hardware, and reports demonstration on Zen 1 and Zen 2 with Zen 3 and Zen 4 suspected but not demonstrated. A mitigation for the Safe RET half is merged into kernel Git and is not yet in a released stable kernel, and no fixed microcode version is named in the available coverage.
  • Why it matters: Deployed Spectre v2 mitigations do not stop this variant, and the reported leak rate is low but sufficient to recover password hashes.
  • Follow-up: Record the stable kernel versions that ship the Safe RET mitigation.

send feedback on this story