Researchers from MIT CSAIL disclosed an interrupt injection attack that can bypass Linux’s Safe RET mitigation for Spectre-class attacks on AMD Zen 1 through Zen 4 processors, potentially allowing information disclosure from kernel memory. AMD acknowledged the issue in its Return Address Security Bulletin and said the weakness stems from Linux’s implementation of the mitigation for Speculative Return Stack Overflow (SRSO) rather than the processor architecture alone. The flaw lets an attacker with code execution on a target system precisely time an interrupt to disrupt branch predictor sanitization and weaken the intended protection.
Linux has already patched the issue in the latest kernel Git code by addressing the handling of interrupts around the Safe RET mitigation path. The researchers reported demonstrating arbitrary kernel memory leakage on AMD Zen 2 systems running Linux with default Spectre v2 defenses, achieving 5.47 bytes per second at 91.97% accuracy and reading /etc/shadow in five of ten attempts. The work was reported by Daniël Trujillo of MIT CSAIL, presented at Black Hat USA, and accompanied by a proposed fix that adds a second predictor neutralization step on interrupt return; researchers also said related misprediction behavior was observed on some Intel systems, though AMD is the vendor that formally assigned and documented the vulnerability.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Safe RET Interrupt Vulnerability was publicly disclosed, with AMD and media reports describing how a precisely timed interrupt could disrupt Linux's Safe RET mitigation. The disclosure identified Zen 1 and Zen 2 as demonstrated targets and noted Zen 3 and Zen 4 could also be affected.
AMD published security bulletin AMD-SB-7061, titled "Safe RET Interrupt Vulnerability," describing an interrupt injection issue affecting Linux's Safe RET mitigation for SRSO on Zen 1 through Zen 4 processors. AMD said the issue appears tied to Linux's implementation and could enable information disclosure if exploited.
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan demonstrated the TONTOU/Interrupt Injection attack against Linux on AMD Zen 2, leaking arbitrary kernel memory at 5.47 bytes per second and extracting /etc/shadow in 5 of 10 runs. They presented the findings at Black Hat USA, showing how the technique bypasses Spectre v2 mitigations by re-poisoning branch prediction state after mitigation cleanup.
A mitigation patch for the Safe RET Interrupt Vulnerability was added to the latest Linux kernel Git code. The change improved SRSO-related kernel handling to address the interrupt window in Linux's Safe RET implementation.
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed the INTERRUPT INJECTION issue to AMD and Intel. The disclosure occurred on February 5, according to The Hacker News.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcethehackernews.com
Open sourcephoronix.com
Open sourceamd.com
Open sourceamd.com
Open sourcepeople.csail.mit.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.