Branch Target Reuse, BTR: New Spectre V2 Attack Targeting JIT Compilers

It's been a while since any new Spectre vulnerabilities have come to light but that's changing today. The embargo has now lifted on BTR, Branch Target Reuse as a new Spectre-V2 attack affecting just-in-time (JIT) compilers. Security researchers at VUSec have announced today Branch Target Reuse as a Spectre-V2 attack in JIT engines affecting the Linux kernel with BPF, Oracle's GraalVM, and also the Mozilla SpiderMonkey JavaScript engine for Firefox. BTR amounts to a speculative execute-after-free primitive with JIT compilers when not invalidating stale indirect branch prediction entries. One of the end-to-end exploits developed by VUSec is for leaking arbitrary memory on modern Intel CPUs in bypassing all enabled mitigations. All processors evaluated by the VUSec team were found to be impacted by Branch Target Reuse including Intel, AMD, and Arm hardware. Hardware vendors are encouraging existing mitigation mechanisms. In July when this was privately disclosed, the Linux kernel landed patches to enabling Indirect Branch Predictor Barrier (IBPB) flush on BPF JIT allocations and support in the BPF kernel code for hardening against JIT spraying. Back in July I covered the kernel changes at the time in Linux 7.2-rc2 BPF Code Being Hardened Against JIT Spraying Attacks. Thus no new Linux kernel mitigations out today as the BPF changes have been mainlined since July and also back-ported already to stable kernel versions. For Oracle GraalVM, randomizing JIT code-cache locations is being done to hinder BTR. Mozilla is said to have evaluated IBPB-based mitigations for SpiderMonkey but instead prioritizing work on site isolation capabilities. Those wanting to learn more about BTR can do so at VUSec.net.

Original Source

Read the full article at Phoronix →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.