JIT Compilers Revive Spectre-v2 Attacks, Google Halts Rewards Program
A new paper shows JIT compilation can revive Spectre-v2 attacks, succeeding against SpiderMonkey, eBPF, and GraalVM, as Google ends its open source vulnerability rewards program.
A new paper demonstrates that Just-In-Time (JIT) compilation systems can be used to revive Spectre-v2 attacks against processors, according to hackaday.com. The researchers targeted several JIT compilers, including the SpiderMonkey JavaScript engine used by Firefox, the eBPF JIT in the Linux kernel, and GraalVM, which is used to run Python. They reported success with each of the targeted JIT compilers.
Updated Linux kernels are available for most distributions, with over 1,200 vulnerability report IDs patched. In a separate development, Google has stopped its Google Open Source Vulnerability Rewards Program because of AI.
Background
In the past, the Spectre class of attacks was discovered to leak behavior by targeting branch prediction. Spectre-v2 showed that non-privileged contexts like non-root users and virtual machines could poison instruction prediction and read arbitrary memory, requiring Linux kernel fixes. Previously, Windows patched over a thousand vulnerabilities in a single Patch Tuesday.
Quick answers
What did the new paper find about Spectre-v2 attacks?
The paper found that JIT compilation can be used to revive Spectre-v2 attacks, with success reported against SpiderMonkey, the eBPF JIT in the Linux kernel, and GraalVM used in Python.
Why did Google stop its Open Source Vulnerability Rewards Program?
Google stopped the program because of AI.
Are there patches available for the Spectre-v2 JIT attacks?
Updated Linux kernels are available for most distributions with over 1,200 vulnerability report IDs patched.