Chinese Loongson processors have leaky caches, researchers find

https://image.theregister.com/5287158.jpg?imageId=5287158&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Attackers could extract data, even working from inside a guest VM

Researchers from Germany’s Helmholtz Center for Information Security have found processors made by China’s Loongson have leaky caches that attackers could use to seek specific data.

Loongson has developed its own LoongArch instruction set architecture (ISA) that blends approaches used by MIPS and RISC-V.

On a site called LoongLeakAttack.com, the researchers explain that they found the leaky cache using a fuzzer, then noticed that the LoongArch ISA manual mentions an instruction that leaves 32 bits of a memory register in an “uncertain” state.

“Our analysis reveals that under certain circumstances, the ‘uncertain’ data originates from the L1 data cache,” the four researchers wrote. “Since this cache is not isolated between applications, LoongLeak can leak data from other applications and the operating system. Even worse, an attacker can prime the CPU’s internal state to target the leakage to a...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more