Chinese Loongson processors have leaky caches, researchers find

← Back to the feed

Chinese Loongson processors have leaky caches, researchers find

The Register · 6 hours ago

Researchers have identified a cache-leakage vulnerability in Chinese Loongson processors that could allow attackers to extract sensitive data from other applications, operating systems and even host machines from within virtual machines. The finding matters because the flaw can be exploited by unprivileged software and appears difficult to detect, potentially affecting systems used under China’s push for domestically produced technology.

The researchers said they recovered full-disk AES keys, partial root-password hashes and bypassed defences including ASLR and stack canaries within seconds. The issue stems from an LoongArch instruction that can expose L1 cache data; software-only mitigation is not considered feasible, although a fix has been incorporated into the Loongson 3A6000, with cache eviction reducing performance by up to 1.4 per cent. Exposure outside China is likely limited because Loongson processors have little international use.

  • Loongson cache flaw can expose sensitive system data.
  • Attacks may work from applications, containers and guest virtual machines.
  • Newer 3A6000 processors include a mitigation.

Research Science

Read the full article at the source →