Back to advisories

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

Researchers disclosed TONTOU, a new CPU-level attack that bypasses Spectre v2 mitigations on Intel and AMD processors. Unprivileged code can exploit a branch predictor window to leak sensitive data including Linux password hashes. This affects all systems running vulnerable CPUs regardless of current patches.

HIGHAdvisoryAug 08, 2026
Action required
Monitor for unusual local process behavior and failed authentication attempts. Coordinate with infrastructure teams to assess CPU vulnerability status. No patch available yet; escalate to vendor security teams for guidance on interim controls.
Affected products
LinuxAMDIntelZen 2