Notorious Spectre CPU vulnerability returns hitting JIT engines via side channel attacks

https://cdn.mos.cms.futurecdn.net/MmSZkX83aFDh9nX7mrMNBK-970-80.jpg
  • New Spectre variant exploits processor prediction behavior in just-in-time compilers
  • Researchers demonstrated practical attacks against Intel-based Linux systems
  • Vendors released mitigations as security teams assess performance tradeoffs

The dreaded Spectre vulnerability which had chip manufacturers scrambling for a fix a few years ago, has returned, experts have claimed.

Security researchers from the Vrije Universiteit in the Netherlands and Scuola Superiore Sant’Anna in Italy published a new report, detailing a type of attack they call Branch Target Reuse (BTR).

They labeled it the first practical in-place Spectre v2 attack that targets just-in-time (JIT) compilers - and it's a lot to decompile (pun intended), so let’s break it all down.

Spectre and Meltdown

Modern microprocessors come with a feature called “speculative execution” - they speculate what a program’s next moves might be, and load them in advance, so that when one scenario actually happens, it can be executed rather quickly.

They also...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more