Find notable cyber news and cases, enriched with sources, timelines, and signals.

INTERRUPT INJECTION TONTOU analysis bypassing Spectre v2 defenses on Linux

Technical Analysis
First reported
Last updated
Happening score
H score 24
2 unique sources, 2 articles

Summary

Hide ▲

MIT CSAIL researchers disclosed INTERRUPT INJECTION, a TONTOU timing primitive that can bypass Spectre v2 defenses on Linux by using unprivileged code to schedule a hardware interrupt during kernel execution. The technique can re-poison branch predictors after neutralization and leak kernel memory on AMD and Intel systems; on an AMD Zen 2 host running Linux version 6.14.0-37-generic, it extracted /etc/shadow contents with 91.97% accuracy at 5.47 bytes/s and succeeded in 5 of 10 attempts, averaging 18 minutes per attempt. On August 6, AMD-SB-7061 named Zen 1 through Zen 4 as affected by the Safe RET Interrupt Vulnerability, and AMD warned that a precise interrupt could weaken Safe RET and lead to information disclosure. The researchers also tied the exploit path to interrupt-handler poisoning and compared the behavior with prior Inception-related RSB pollution techniques.

Related Happenings

AMD Zen 1 through Zen 4 Safe RET Interrupt security flaw

Vulnerability
H score37 First: 06.08.2026 19:17 Last: 06.08.2026 19:17 Sources 1

How related: AMD published a bulletin on August 6, AMD-SB-7061, titled "Safe RET Interrupt Vulnerability," naming Zen 1 through Zen 4 processors as affected.

About this happening: Safe RET Interrupt Vulnerability affects Zen 1 through Zen 4 processors, where a local attacker can time an interrupt injection to weaken Safe RET and expose kerne...

Linux kernel traffic-control use-after-free race public exploit privilege-escalation flaw (CVE-2026-53264)

Vulnerability
H score28 First: 28.07.2026 11:04 Last: 28.07.2026 11:04 Sources 1

About this happening: Public exploit code for CVE-2026-53264 turns a Linux kernel traffic-control use-after-free race into local privilege escalation to root on affected builds. The dem...

Linux kernel XFRM ESP-in-TCP local privilege escalation (CVE-2026-46300)

Vulnerability
H score35 First: 14.05.2026 10:06 Last: 14.05.2026 10:06 Sources 1

About this happening: Fragnesia adds a fresh Linux kernel local privilege-escalation path, putting unprivileged local attackers on a route to root access across major distributions. The...

Latest development: 14.05.2026 16:00

Cloud security firm Wiz identified Fragnesia (CVE-2026-46300) in the Dirty Frag family, a Linux local privilege escalation that lets unprivileged local users gain root by corrupting the kernel page cache of read-only files. William Bowling of Zellic and the V12 team were credited with the discovery, and a working proof-of-concept exploit was published on May 13, 2026.

Linux kernel Dirty Frag local root escalation privilege-escalation flaw

Vulnerability
H score30 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...

IP KVM devices unauthenticated root access and command execution flaws (multiple vulnerabilities)

Vulnerability
H score39 First: 18.03.2026 13:42 Last: 18.03.2026 13:42 Sources 1

About this happening: Nine IP KVM vulnerabilities across GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, and JetKVM can expose attached hosts to root access and comm...

Timeline

  1. 06.08.2026 19:17 1 articles · 2h ago

    Researchers disclose INTERRUPT INJECTION to AMD and Intel

    Initial Disclosure

    MIT CSAIL researchers Daniël Trujillo and Mengjia Yan disclosed INTERRUPT INJECTION to AMD and Intel on February 5 after developing an unprivileged Linux timing attack that can place a hardware interrupt between branch-predictor sanitization and kernel use.

    Show sources
  2. 06.08.2026 19:17 3 articles · 2h ago

    AMD publishes Safe RET bulletin as researchers present INTERRUPT INJECTION

    Technical Analysis Update

    On August 6, AMD published AMD-SB-7061, naming Zen 1 through Zen 4 processors as affected by Safe RET Interrupt Vulnerability and warning that a precise interrupt could weaken Safe RET and lead to information disclosure. MIT CSAIL researchers also presented INTERRUPT INJECTION at Black Hat USA that day, showing arbitrary kernel memory leakage on an AMD Zen 2 system running Linux 6.14 and reading /etc/shadow in five of ten attempts.

    Show sources