Loongson Processors Found with Leaky Caches by Researchers
TL;DR. Researchers discovered a critical cache vulnerability in Chinese Loongson processors, enabling data extraction across applications and virtual machines. - The 'LoongLeak' flaw allows attackers to recover sensitive information, including AES keys and root password hashes. - The vulnerability exploits an architectural design in the LoongArch ISA, not relying on traditional side-channel methods. - Software mitigations are ineffective, meaning affected users face significant hardware security risks.
- German researchers identified a 'LoongLeak' vulnerability in Chinese Loongson processors.
- The flaw allows attackers to extract data from L1 data caches, even from within virtual machines.
- Attackers can recover sensitive information like AES keys and partial root password hashes within seconds.
- The vulnerability is architectural within the LoongArch instruction set, bypassing typical software defenses.
Sources
- Chinese Loongson processors have leaky caches, researchers find — theregister.com