TONTOU Attack Bypasses Spectre v2 Fixes to Leak Linux Kernel Memory on AMD CPUs
Researchers presenting at USENIX Security 2026 disclosed a new CPU side-channel attack called TONTOU, which exploits timer interrupt timing to re-poison branch predictor state after Spectre v2 defenses have neutralized it but before the kernel uses the branch. The technique allows an unprivileged local attacker to speculatively read kernel memory, including sensitive data such as password hashes from /etc/shadow. Demonstrated on AMD Zen 2 hardware running Linux, the attack achieved a leak rate of 5.47 bytes per second at 91.97% accuracy, recovering /etc/shadow-equivalent data in roughly 18 minutes across successful attempts. The attack also combines with the Inception technique for targeted data extraction, and researchers noted a theoretical applicability to Intel eIBRS, though that path requires additional software conditions. Because the exploit generates no normal file-access or authentication events, it is difficult to detect with standard endpoint tools, though restricting high-resolution timers and isolating untrusted code are cited as mitigations.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in