Urgent.News

What's breaking now, across thousands of outlets.

Science

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Eight years on, we're still paying to hide the future glimpsed during speculative execution

Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible

Despite a perception that the notorious Spectre security vulnerabilities were resolved in 2018, researchers have discovered that certain RISC-V chips remain susceptible to these threats. Spectre is a collection of vulnerabilities related to speculative execution, a performance enhancement technique that involves predicting data flow before instructions are executed.

Incorrect predictions leave traces that can be exploited to bypass memory protections and access sensitive information. Initially believed to affect only x86 and ARM chips, researchers found that commercially available out-of-order RISC-V processors, such as SiFive P550 and T-Head Xuantie C910/C920, are vulnerable to all major Spectre variants.

These processors process instructions out of order, unlike the in-order processors (SiFive U74, Xuantie C906, C908), which do not appear to be vulnerable. The researchers demonstrated proof-of-concept attacks on these vulnerable processors using Spectre-PHT, Spectre-BTB, SpectreRSB, and Spectre-STL techniques, achieving up to 100% recall with over 97% precision.

Spectre-PHT manipulates the Pattern History Table, Spectre-BTB corrupts the Branch Target Buffer, Spectre-RSB targets the Return Stack Buffer, and Spectre-STL exploits mispredicted store-to-load forwarding. The researchers created an exploit to leak arbitrary Linux kernel memory on the Xuantie C910 at a rate of 338 bytes per second.

While software-based defenses exist for x86 and ARM hardware, these techniques may not be directly transferable to RISC-V. The researchers also criticize the lack of introspection interfaces in RISC-V hardware, which hinders the ability to observe and analyze microarchitectural features. They argue that the diversity of RISC-V hardware makes it unlikely that a single mitigation strategy will protect all systems.

The authors emphasize the need for architectural primitives, hardware transparency, and ecosystem-wide tooling to effectively defend against Spectre vulnerabilities. They disclosed their findings last December, and three of their patches have been merged into mainline Linux, while two others are under review. SiFive and T-Head (Alibaba) have responded to the vulnerabilities accordingly, with SiFive addressing P550-specific issues and T-Head committing to publishing ad-hoc speculation barriers for their processors.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Science

Solar eclipse plunges Spain into darkness

After it first appeared in the remote Arctic region of northern Russia and made its way south to Rejkjavik, the eclipse – the first in mainland Europe since 2006 – drew huge crowds in Spain.

More from Wednesday 12 August →