By Interestana AI Editorial — AI-drafted, human-overseen. How we report
New Spectre Variant Leaks Linux Root Password Hashes
A new variant of the Spectre vulnerability, identified as a Branch Target Reuse (BTR) attack, has been demonstrated to extract root password hashes from Intel processors running Linux operating systems in an average of 3 to 5 minutes. This exploit targets a specific speculative execution flaw within Intel CPUs, allowing attackers to infer sensitive information that is otherwise protected. The researchers behind the discovery have detailed the methodology, which involves carefully crafted sequences of instructions that trigger speculative execution paths. By observing the side effects of these speculative operations, specifically cache timing differences, the attack can reconstruct portions of the data being processed, including the highly sensitive root password hash.
The BTR attack operates by exploiting the processor's tendency to speculatively execute instructions beyond the current program flow. In this case, the attack leverages the Branch Target Buffer (BTB), a component of the processor that predicts the target of indirect branches. By manipulating the BTB, the attacker can cause the processor to speculatively execute code that accesses memory locations containing the password hash. The subsequent rollback of this speculative execution, due to the incorrect prediction, leaves traces in the processor's cache that can be measured and analyzed to reveal the hash. This process bypasses traditional memory protection mechanisms, as the data is never explicitly read by the malicious code but rather inferred through side-channel analysis.
This discovery builds upon previous Spectre and Meltdown vulnerabilities, which first highlighted the dangers of speculative execution in modern CPUs. While earlier attacks focused on extracting arbitrary kernel memory, this new BTR variant specifically targets the retrieval of password hashes, a critical component for system authentication and privilege escalation. The speed at which the attack can be executed, within minutes, makes it particularly concerning for systems that may not be immediately patched or updated. The researchers have indicated that the attack is effective against a range of Intel processors, underscoring the widespread potential impact.
Mitigation strategies for this new BTR attack are expected to involve microcode updates from Intel and potentially operating system-level patches to disable or restrict the vulnerable speculative execution paths. However, such mitigations often come with a performance overhead, as they involve disabling or modifying features that contribute to processor speed. The ongoing research into speculative execution vulnerabilities continues to pose a significant challenge for CPU manufacturers and system administrators, requiring continuous vigilance and adaptation to protect sensitive data. The ability to extract root password hashes so rapidly presents a direct threat to the integrity and security of Linux systems, potentially enabling unauthorized access and further compromise.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.