Breaking the Barrier: Post-Barrier Spectre Attacks
Johannes Wikner, Kaveh Razavi
Abstract
The effectiveness of transient execution defenses rests on obscure model-specific operations that must be correctly implemented in microcode and applied by software. In this paper, we study branch predictor invalidation through Indirect Branch Predictor Barrier (IBPB) for x86 processors, which is a cornerstone defense against cross-context and cross-privilege Spectre attacks, and discover new vulnerabilities in both its microcode implementation and application by software. Concretely, we demonstrate two new post-barrier speculative return target hijacks on Intel and AMD CPUs. First, we show an end-to-end cross-process attack that leaks the hash of the root password from a suid process. This attack works despite IBPB on recent generations of Intel processors due to a microcode implementation flaw. Second, we show that an unprivileged attacker can leak privileged memory on AMD Zen 1(+)/2 processors despite the deployed IBPB mitigation, due to how IBPB is applied by the Linux kernel. We propose using a chicken bit to disable exploitable return predictions on affected Intel CPUs and a software patch for the Linux kernel to safely use IBPB on affected AMD CPUs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 91a3d405-6564-4c9f-8afd-1ac24e401677Cited by top-tier papers10
- Place Protections at the Right Place: Targeted Hardening for Cryptographic Code against Spectre v1Yiming Zhu, Wenchao Huang, Yan XiongUSENIX Security 2025
- Phantom Trails: Practical Pre-Silicon Discovery of Transient Data LeaksAlvise de Faveri Tron, Raphael Isemann, Hany Ragab, Cristiano Giuffrida et al.USENIX Security 2025
- GhostCache: Timer- and Counter-Free Cache Attacks Exploiting Weak Coherence on RISC-V and ARM ChipsYu Jin, Minghong Sun, Dongsheng Wang, Pengfei Qiu et al.CCS 2025
- Training Solo: On the Limitations of Domain Isolation Against Spectre-v2 AttacksSander Wiebing, Cristiano GiuffridaS&P 2025
- Transient Architectural Execution: From Weird Gates to Weird ProgramsPing-Lun Wang, Fraser Brown, Riccardo Paccagnella, Eyal Ronen et al.S&P 2026
Builds on16
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- ret2spec: Speculative Execution Using Return Stack BuffersGiorgi Maisuradze, Christian RossowCCS 2018 · 282 citations
- SMoTherSpectre: Exploiting Speculative Execution through Port ContentionAtri Bhattacharyya, Alexandra Sandulescu, Matthias Neugschwandtner, Alessandro Sorniotti et al.CCS 2019 · 267 citations
- InSpectre Gadget: Inspecting the Residual Attack Surface of Cross-privilege Spectre v2Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, Cristiano GiuffridaUSENIX Security 2024 · 32 citations
- Exploring Branch Predictors for Constructing Transient Execution TrojansTao Zhang, Kenneth Koltermann, Dmitry EvtyushkinASPLOS 2020 · 32 citations
Related papers
- RETBLEED: Arbitrary Speculative Code Execution with Return InstructionsJohannes Wikner, Kaveh RazaviUSENIX Security 2022
- Branch Privilege Injection: Compromising Spectre v2 Hardware Mitigations by Exploiting Branch Predictor Race ConditionsSandro Rüegge, Johannes Wikner, Kaveh RazaviUSENIX Security 2025
- Branch History Injection: On the Effectiveness of Hardware Mitigations Against Cross-Privilege Spectre-v2 AttacksEnrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos et al.USENIX Security 2022
- Defeating Transient Execution Attacks by Limiting Secret Reachability Through Register Hiding and ShadowCFIDaniël Trujillo, Jagadish Kotra, David Kaplan, Mengjia YanS&P 2026 · 1 citation
- Uncovering and Exploiting AMD Speculative Memory Access Predictors for Fun and ProfitChang Liu, Dongsheng Wang, Yongqiang Lyu, Pengfei Qiu et al.HPCA 2024 · 9 citations
