A new Retbleed speculative execution attack can bypass Retpoline's workaround and infect Intel and AMD processors.
Security researchers have discovered a new speculative execution attack called Retbleed that affects processors from both Intel and AMD and could be used to extract sensitive information.
Retbleed focuses on return instructions, which are part of the retpoline software mitigation against the class of speculative execution attacks that became known since early 2018, with Spectre.
The problem affects Intel Core processors from the 6th generation (Skylake – 2015) to the 8th (Coffee Lake – 2017) and AMD Zen 1, Zen 1+, Zen 2 released between 2017 and 2019.

Speculative execution is an optimization technique that allows CPUs to perform calculations before knowing whether they are required by future tasks.
See also: Quantum ransomware: Attack affects 657 healthcare organizations
When the destination address is known, a direct branch contained in the instruction is followed. An indirect branch occurs when there is no indication of the destination, but it is predicted from already executed branches.
Spectre attacks exploit these predictions, tricking the processor into executing instructions that require sensitive data from memory.
Retpoline has released a software-based solution to mitigate speculative execution attacks using rollback functions to isolate indirect branches.
However, researchers at ETH Zurich have found a way to enforce return function predictions as in the case of indirect branches and to insert branch targets into the kernel address space, regardless of user privileges.
"We found that we can enable microarchitectural conditions, in both AMD and Intel CPUs, that force returns to be predicted as implicit branches. We also built the necessary tools to discover locations in the Linux kernel where these conditions are met."

“We found that we can enter branch targets that are within the kernel address space, even as unprivileged users. Although we cannot access branch targets within the kernel address space — branching to such a target results in a page fault — the Branch Prediction Unit will be informed upon observing a branch and assume that it was executed legally, even if it is at a kernel address.”
See also: SHI International: Hit by malware attack
The researchers further explain in a technical paper on Retbleed that using an accurate branch history on Intel processors, it is possible to hack all return instructions that "follow sufficiently deep call stacks.".
In the case of AMD processors , it is possible to violate any return instructions if the previous branch destination was correctly selected during the branch attack.
The researchers also published a video showing how Retbleed can be used to leak kernel memory on Intel and AMD processors:
For Intel processors, the vulnerability is tracked as CVE-2022-29901. Intel has released a security advisory that recommends using Indirect Branch Restricted Speculation (IBRS) instead of retpoline.
IBRS is available by default on Windows systems, so no update is required. Intel has worked with the Linux community to create updates that address the Retbleed issue.
For AMD, Retbleed is tracked as CVE-2022-29900. The company has published guidance on mitigating the issue that could lead to the disclosure of sensitive information.
Although ETH Zurich researchers developed a Retbleed proof of concept (PoC) only for Linux, the vulnerability also affects other operating systems, because it is hardware-related.
The technical paper for Retbleed has been published, and the researchers will present the vulnerability on August 10th at the Usenix Security.
Source: bleepingcomputer.com
