Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible
Eight years on, we're still paying to hide the future glimpsed during speculative execution
A recent study reveals that certain RISC-V chips are still vulnerable to the Spectre security flaws, debunking the assumption that the architecture is immune due to its simplicity. Spectre is a family of vulnerabilities associated with speculative execution, a performance optimization technique that can be exploited to access secrets and violate memory protections.
The researchers from Belgium and Germany tested commercially available out-of-order RISC-V processors, such as SiFive P550 and T-Head Xuantie C910/C920, and found that they are susceptible to all major Spectre variants. They demonstrated proof-of-concept attacks using Spectre-PHT, Spectre-BTB, SpectreRSB, and Spectre-STL, achieving up to 100% recall with over 97% precision.
The paper suggests that the lack of introspection interfaces in RISC-V hardware and the diversity of the hardware ecosystem make it challenging to develop a unified mitigation strategy. The researchers have already disclosed their findings responsibly, with three patches merged into mainline Linux and two others under review. However, they argue that closing the gap in Spectre defense requires building architectural primitives, hardware transparency, and ecosystem-wide tooling, rather than simply porting individual mitigations from other architectures.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.