Interrupt Injection Attack: Bypassing Spectre v2 Defenses on Intel and AMD CPUs (2026)

The world of cybersecurity is once again in a frenzy, as researchers have uncovered a new and insidious attack vector that threatens the very foundations of our digital security. The latest exploit, dubbed 'Interrupt Injection' by MIT CSAIL researchers Daniël Trujillo and Mengjia Yan, is a cunning and insidious technique that can bypass even the most robust defenses against Spectre v2 vulnerabilities on Intel and AMD CPUs.

What makes this attack particularly insidious is its simplicity and the fact that it requires no privileges, only local code execution. This means that the risk is not limited to a single user or system, but rather extends to shared systems running affected processors. The implications are far-reaching, as the attack can potentially leak arbitrary kernel memory, allowing attackers to access sensitive information such as password hashes stored in the /etc/shadow file.

The researchers disclosed the vulnerability to AMD and Intel on February 5, and AMD has since acknowledged the issue and released a bulletin, AMD-SB-7061, titled 'Safe RET Interrupt Vulnerability'. The bulletin names Zen 1 through Zen 4 processors as affected and warns that an attacker running code on an affected system could inject an interrupt at a precise moment to disrupt Safe RET, potentially weakening that protection and resulting in information disclosure.

However, the bulletin fails to provide a clear path for defenders to determine whether a given machine has already received the patch. With no version number, commit, or CVE to check against, administrators are left in a state of uncertainty. The kernel reports SRSO status at /sys/devices/system/cpu/vulnerabilities/specrstackoverflow, but the documentation defining that file's values does not mention interrupts, leaving defenders in a difficult position.

Intel, on the other hand, does not consider a mitigation necessary, according to the paper shared with The Hacker News. The company's guidance, INTEL-SA-00598, does not mention interrupts, and Intel has paid a discretionary bug bounty bonus without requiring a mitigation. The researchers propose a second neutralization on the way out of an interrupt, but this would come at a performance cost that is not quantified in the paper.

The attack, known as TONTOU (Time-of-Neutralization to Time-of-Use), takes advantage of the fact that interrupts can fire almost anywhere and that Linux allows any user to schedule them with nanosecond granularity. This means that interrupt handling can execute between neutralization and use, effectively bypassing the Spectre v2 defense even when the mitigation was designed around kernel entry or return.

The researchers widened their odds by evicting those bytes from L1 and L2 cache using a sibling hyperthread, slowing them down, and by picking the write syscall, which left them controlling two registers. Interrupts landed inside the window 5% to 12% of the time, and around 2% with those registers under attacker control. Once inside, the handler itself became the training gadget, armed with Inception (CVE-2023-20569) to fill the return stack buffer with an attacker-chosen target.

The attack was demonstrated on AMD Zen 2 and Zen 4 processors, with success rates of 0.75% on Zen 2, 0.22% on Intel Arrow Lake, and 0.037% on Cascade Lake Refresh. Zen 4 produced no mispredictions in that test, and no end-to-end leak was demonstrated on Intel, where the attacker would also need a usable disclosure gadget already in the kernel.

However, the researchers believe that an end-to-end attack is possible on Intel by combining their Interrupt Injection primitive with prior work that has already shown the existence of disclosure gadgets in kernels. This is a concerning development, as it highlights the ongoing challenge of securing our digital systems against sophisticated and evolving threats.

In conclusion, the discovery of the Interrupt Injection attack is a stark reminder of the ongoing need for vigilance and innovation in the field of cybersecurity. As we continue to develop new technologies and systems, it is crucial that we remain one step ahead of the attackers and ensure that our defenses are robust and effective. The future of our digital security depends on it.

Interrupt Injection Attack: Bypassing Spectre v2 Defenses on Intel and AMD CPUs (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Rob Wisoky

Last Updated:

Views: 6432

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.