New TONTOU Attack Leverages Spectre v2 Bypass to Leak Linux Password Hashes

New TONTOU Attack Leverages Spectre v2 Bypass to Leak Linux Password Hashes

First seen 7 Aug 2026, 10:55 UTC BleepingcomputerFeeds.4Sysopswww.amd.comblackhat.com 87% similarity 71.0

Article Content

Browse articles
ThreatCluster

Researchers have discovered a new attack method named TONTOU that bypasses Spectre v2 mitigations on AMD and Intel processors. This exploit allows unprivileged code to leak sensitive data, including Linux password hashes, from kernel memory. The attack exploits a timing vulnerability between the neutralization of branch predictors and their subsequent use, enabling attackers to re-poison the CPU state. The technique involves using timer interrupts to manipulate the processor's indirect branch predictor. An AMD kernel fix is already available, but many shared hosts remain vulnerable until administrators apply the patch and review their workload isolation. The researchers demonstrated the attack on an AMD Zen 2 host with the latest mitigations in place. This discovery highlights the ongoing risks associated with speculative execution vulnerabilities.

Key Points: • The TONTOU attack can leak sensitive data from Linux systems by bypassing Spectre v2 mitigations. • Unprivileged code can exploit the timing gap in branch predictor neutralization to extract password hashes. • An AMD kernel fix is available, but many systems remain at risk until patches are deployed.

ThreatCluster AI How this analysis works

Timeline

2026-08-06
TONTOU attack technique revealed
Researchers at MIT disclosed a new attack that bypasses Spectre v2 mitigations, allowing data leaks from Linux systems.
BleepingComputer
2026-08-07
AMD kernel fix released
An update to mitigate the TONTOU attack has been made available, but many shared hosts remain vulnerable until applied.
Feeds.4Sysops

Community

Browse all →