Chinese Loongson processors have leaky caches, researchers find
Attackers could extract data, even working from inside a guest VM
German researchers from the Helmholtz Center for Information Security have discovered that Chinese Loongson processors have leaky caches, which could allow attackers to retrieve specific data. The Loongson processor uses its own LoongArch instruction set architecture (ISA), which incorporates elements from MIPS and RISC-V. The researchers found the leaky cache using a fuzzer and noticed that a specific instruction in the LoongArch ISA manual leaves 32 bits of a memory register in an "uncertain" state.
This "uncertain" data is derived from the L1 data cache, which is not isolated between applications. Consequently, LoongLeak, as named by the researchers, can leak data from other applications and the operating system. The attackers can prime the CPU's internal state to target the leakage to a specific cache set. The researchers shared case studies that demonstrate the recovery of full-disk AES keys from the kernel, partial root password hashes from user-space, and bypassing traditional software defenses, such as Address Space Layout Randomization (ASLR) and stack canaries.
What makes this issue even more concerning is that LoongLeak can be exploited from unprivileged user space, containers, or virtual machines, and it can even cross the virtual machine boundary to leak host data inside a VM. Unlike traditional side-channel amplification, LoongLeak requires no high-resolution timers and grants the attacker precise control over cache set and line offset.
Since the flaw is architectural, software mitigations are not feasible. Users with affected chips need to replace them or ensure no private data enters or remains in the L1 cache, which may involve disabling one thread per core, effectively disabling hyperthreading. Loongson has fixed the flaw in an update to its model 3A6000 processor, but the performance degradation caused by eviction of cache data is only 1.4 percent in the worst-case scenario.
However, the blast radius is likely limited, as Loongson chips are not widely used outside China. Promoted by China's government as an alternative to imported technology, Loongson chips are used in PCs, servers, and appliances like printers. Lenovo sells laptops using Loongson chips solely in China. While other major PC manufacturers have been approached about adopting the processors, none have done so so far.
Nonetheless, China's government may be concerned about the research, as it has instructed public sector buyers to purchase local products. The researchers could not find specific tools or methods to detect if LoongLeak is being exploited, leaving users at risk.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Chinese Loongson processors have leaky caches, researchers find theregister.com