Chinese Loongson processors have leaky caches, researchers find
Attackers could extract data, even working from inside a guest VM
German cybersecurity researchers have discovered that processors made by China's Loongson have leaky caches that could be exploited by attackers to access specific data. Loongson has developed its own LoongArch instruction set architecture (ISA), which combines concepts from MIPS and RISC-V. The researchers found the leaky cache using a fuzzing tool, and noted that the LoongArch ISA manual references an instruction that leaves 32 bits of a memory register in an "uncertain" state.
This "uncertain" data originates from the L1 data cache, which is not isolated between applications, allowing attackers to leak data from other applications and the operating system. Even more concerning, an attacker can manipulate the CPU's internal state to target specific cache sets. The researchers demonstrated that LoongLeak can recover full-disk AES keys from the kernel, extract partial root password hashes from user-space, and bypass traditional software defenses like ASLR and stack canaries.
The flaw can be exploited from unprivileged user space, containers, or virtual machines, and even crosses virtual machine boundaries to leak host data. The researchers warn that software mitigations are not possible, as users with affected chips must either replace them or avoid storing private data in the L1 cache, which may require disabling hyperthreading.
Loongson addressed the flaw in a firmware update to its model 3A6000 processor, resulting in a 1.4 percent performance slowdown. The vulnerability is likely limited in impact since Loongson chips are mostly used in China, where the government promotes their use to reduce dependence on foreign technology. While major PC manufacturers have shown interest in adopting Loongson chips, none have publicly adopted them outside of China.
The Chinese government encourages local product usage, potentially putting government agencies in the position of running vulnerable devices. The researchers found no specific tools to detect LoongLeak exploitation.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Chinese Loongson processors have leaky caches, researchers find theregister.com