The hardware restrictions introduced in Intel and ARM processors in recent years to fix a serious vulnerability called Spectre are not as strong as they seem. Researchers have devised a new attack method that can overcome the restrictions, but exploiting it is not as easy as it was with the original flaw.
The new vulnerability, discovered by researchers from the Systems and Network Security Group at VU Amsterdam, is called Spectre-BHI (Branch History Injection) or Spectre-BHB (Branch History Buffer) after Intel and ARM have given it different names. According to the research team, it is an extension of the 2017 Spectre version 2 attack, also known as Spectre-BTI (Branch Target Injection), and is similar to Spectre v2 in that it can leak sensitive information from kernel memory.

The exploit created by VUSec researchers helps leak the root password hash from the /etc/shadow using an unprivileged account. The /etc/shadow file is a system file in Linux that is only accessible to the root administrator account. Essentially, the exploit forces the kernel to load the file into memory, where it would normally be protected from access by unprivileged processes, but then leverages the Spectre-BHI vulnerability to access and leak its contents. This is a major security breach in modern operating systems that separates user-mode applications and the kernel memory space in the kernel.
See also: SharkBot: Spread via fake Android Antivirus App on Google Play Store
Spectre is a class of security vulnerabilities that was first disclosed in January 2017. This vulnerability stems from a performance-related feature of modern CPUs called speculative execution, where the CPU tries to predict in advance which path a program's execution will take when it reaches a conditional branch and executes tasks on that path in advance. If this prediction is unreliable, the results stored in CPU caches are discarded. Speculative execution vulnerabilities like Spectre trick this mechanism into leaking information from caches that act as side channels.

Specifically, the researchers report that at the time Spectre was discovered, it was easy to exploit Branch Target Injection (BTI or Spectre-v2), its most dangerous variant. For example, an attacker could inject any branch target into the implicit branch predictor and as a result trick the kernel into jumping to the location of the injected code and executing it.
In an attempt to mitigate the vulnerability, software vendors such as Google and Linux developers found workarounds based on new software, such as retpoline. Although these workarounds were effective, they were fatal to processor performance, which CPU vendors later countered with defenses introduced at the hardware level. Intel's defense is called EIBRS and ARM is called CSV2.
Essentially, hardware defense enables the predictor to monitor the privilege level (user/kernel) a target is running in. If the target is at a low privilege level, the kernel will not use it.
The problem, however, is that the CPU predictor relies on a global history to select target writes to execute. However, the global history can be easily tampered with. In other words, while the original Spectre v2 allowed attackers to inject code locations and then trick the kernel into executing them, the new Spectre-BHI/BHB vulnerability can only cause the kernel to incorrectly predict and execute code snippets that are already in the history and have been executed in the past, but could potentially leak data.

So do Intel eIBRS and Arm CSV2 work? The vulnerability mitigations work as intended, but the remaining attack surface is much larger than vendors initially assumed. However, finding exploitable devices is more difficult than before, as an attacker cannot directly inject intended code outside of the privilege boundaries.
Intel is tracking the new Spectre-BHI vulnerability as CVE-2022-0001, for the multi-privilege version, and as CVE-2022-0002 for the single-privilege version. ARM is tracking it as CVE-2022-23960 for both variants.
According to Intel, most of the company's CPUs are affected by the vulnerability except for those in the Atom family. For ARM, the vulnerable processors are the following: Cortex-A15, Cortex-A57, Cortex-A72, Cortex-A73, Cortex-A75, Cortex-A76, Cortex-A76AE, Cortex-A77, Cortex-A78, Cortex-A78A7, Cortex-A78A7, , Cortex-X1, Cortex-X2, Cortex-A710, Neoverse N1, Neoverse N2 and Neoverse V1. At the same time, both companies have released available software to mitigate the vulnerability, while ARM has five different defenses depending on the system it runs on.
See also: Mercado Libre confirms source code data breach
To create the Linux exploit , VUSec researchers abused eBPF, a technology available since kernel 4.4 that can run sandboxed programs in an operating system kernel. Although eBPF is not part of the problem and even other code can leak information, the presence of unprivileged eBPF greatly facilitates speculative execution attacks. For this reason, researchers recommend disabling it, and some Linux distributions have started disabling it by default.
Source: csoonline.com
