Hardware

Loongson processors vulnerable to LoongLeak cache attack

concept of leaky software, data with a tap sticking out.3d illustration

Researchers have identified a significant security vulnerability in processors manufactured by China's Loongson, dubbed LoongLeak. This flaw allows attackers to potentially access sensitive data by exploiting leaky caches within the chips, with further coverage provided by The Register.

German researchers from the Helmholtz Center for Information Security discovered that Loongson processors, which utilize the LoongArch instruction set architecture, possess caches that leak data. This leakage can be exploited to extract specific information, including full-disk encryption keys and password hashes, from other applications and the operating system. The vulnerability, detailed on LoongLeakAttack.com, can be exploited from unprivileged user space, containers, and even virtual machines, potentially crossing boundaries to leak host data.

Software mitigations are not feasible, requiring hardware replacement or disabling hyperthreading. While Loongson has addressed the flaw in its 3A6000 processor model, and performance impact is minimal, the limited adoption of Loongson chips outside China may restrict the attack's blast radius. However, the Chinese government's push for domestic technology could mean vulnerable devices are in use within public sectors, making detection of exploitation challenging.

Source: The Register

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds